Description
Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.
Published: 2026-07-13
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

MailerPress plugin contains an incorrect privilege assignment flaw. The vulnerability arises when the plugin does not correctly restrict the assignment of roles, allowing an attacker to elevate their privileges. This can lead to unauthorized access to administrative functions, data exposure, or further exploitation. The weakness is mapped to CWE-266, which denotes unauthorized privilege escalation.

Affected Systems

The affected product is the MailerPress plugin developed by the MailerPress Team. Versions from the earliest release through 2.0.2 are vulnerable; no specific earlier version is quoted, so all releases up to and including 2.0.2 must be considered at risk.

Risk and Exploitability

The CVSS score of 8.8 signals a high severity vulnerability. The EPSS score at less than 1% indicates that, while the exploitation likelihood is low, it remains possible and has not been catalogued by CISA KEV. Based on the description, it is inferred that an attacker needs some level of authenticated access to the WordPress site, though the flaw may enable escalation from a lower role to higher privileges. Once escalated, the attacker can manipulate site content, gain administrative control, or exfiltrate sensitive information.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the MailerPress plugin to the latest available version or remove it until a newer release is published. This action resolves the privilege assignment flaw.
  • Apply the principle of least privilege to all WordPress roles and limit the capability set granted to plugin users, ensuring that only review audit logging for role and capability changes so that any unauthorized privilege modifications are detected and investigated promptly.
  • If a patch is not yet available, temporarily disable the plugin or disable role assignment features within the plugin’s settings to prevent further privilege escalation.

Generated by OpenCVE AI on July 31, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Mailerpress Team
Mailerpress Team mailerpress
Wordpress
Wordpress wordpress
Vendors & Products Mailerpress Team
Mailerpress Team mailerpress
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in MailerPress Team MailerPress mailerpress allows Privilege Escalation.This issue affects MailerPress: from n/a through <= 2.0.2.
Title WordPress MailerPress plugin <= 2.0.2 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Mailerpress Team Mailerpress
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:45:11.127Z

Reserved: 2026-06-24T12:46:27.805Z

Link: CVE-2026-57410

cve-icon Vulnrichment

Updated: 2026-07-13T13:45:00.835Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment