Description
Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation.

This issue affects PrivateContent: from n/a through 9.9.2.
Published: 2026-07-01
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The LCweb PrivateContent plugin for WordPress contains an Incorrect Privilege Assignment flaw that allows a lower‑level user to assume higher‑level or administrator privileges. This flaw compromises control over site content and functions by enabling unauthorized privilege escalation.

Affected Systems

The LCweb PrivateContent plugin for WordPress, version 9.9.2 and earlier, is affected. All releases from the initial version up to and including 9.9.2 contain the privilege assignment flaw.

Risk and Exploitability

The CVSS score of 9.8 signals a critical severity for this flaw. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no publicly confirmed exploitation yet. The attack vector most likely involves a legitimate user’s interaction with the plugin, as the vulnerability arises from incorrect privilege assignment during normal operation.

Generated by OpenCVE AI on July 22, 2026 at 14:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the LCweb PrivateContent plugin to the latest version released after 9.9.2 to apply the fix.
  • If an updated version is not available, temporarily disable or remove the PrivateContent plugin capabilities and enforce the principle of least privilege, ensuring that ordinary users do not have administrator rights unless explicitly required.
  • Conduct a user role audit, removing any users with administrator privileges who do not have a legitimate need, and restrict default plugin permissions to the minimum required roles.

Generated by OpenCVE AI on July 22, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Lcweb
Lcweb privatecontent
Wordpress
Wordpress wordpress
Vendors & Products Lcweb
Lcweb privatecontent
Wordpress
Wordpress wordpress

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a through 9.9.2.
Title WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Lcweb Privatecontent
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-01T14:25:49.078Z

Reserved: 2026-06-25T08:03:50.157Z

Link: CVE-2026-57692

cve-icon Vulnrichment

Updated: 2026-07-01T13:51:17.346Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-22T14:30:17Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment