Description
Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
Published: 2026-07-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an incorrect privilege assignment that allows a user with lower permissions to gain higher roles without proper authorization. Identified as CWE-266, this flaw enables privilege escalation by assigning elevated privileges directly within the MailOptin plugin. The impact is that an attacker could potentially acquire administrator access and control over the WordPress site, compromising confidentiality, integrity, and availability of site content and configuration.

Affected Systems

The affected product is the properfraction MailOptin plugin for WordPress. All installations using version 1.2.77.3 or earlier are impacted; no other vendors or product versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector involves an authenticated user who has plugin access exploiting the privilege assignment flaw to elevate their own role level.

Generated by OpenCVE AI on August 1, 2026 at 10:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MailOptin plugin to the latest version that fixes the privilege assignment bug; if no patch is available, disable or uninstall the plugin until an update is released.
  • Audit all WordPress user accounts to confirm the intended role hierarchy; remove any accounts with unusually high privileges that are not required for normal operations.
  • Restrict MailOptin plugin access to trusted administrators only, and verify that any custom code interacting with the plugin validates role changes against WordPress core role definitions to prevent unauthorized privilege escalation.

Generated by OpenCVE AI on August 1, 2026 at 10:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Properfraction
Properfraction mailoptin
Wordpress
Wordpress wordpress
Vendors & Products Properfraction
Properfraction mailoptin
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a through <= 1.2.77.3.
Title WordPress MailOptin plugin <= 1.2.77.3 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Properfraction Mailoptin
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:58:18.279Z

Reserved: 2026-06-25T08:05:16.224Z

Link: CVE-2026-57813

cve-icon Vulnrichment

Updated: 2026-07-13T13:58:14.648Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment