Description
The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities — including `manage_capabilities`, `manage_capabilities_roles`, `manage_capabilities_settings`, and `manage_capabilities_backup` — via a hard-coded `$eligible_roles = ['administrator', 'editor']` assignment that runs automatically on the first `admin_init` after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with `cme_`, `capsman`, `pp_capabilities`, or `presspermit` via `update_option()`. The escalation stops short of full Administrator access, as WordPress's `map_meta_cap` layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on `manage_capabilities_*` capabilities remains fully accessible.
Published: 2026-09-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update Plugin
AI Analysis

Impact

The PublishPress Capabilities plugin for WordPress contains a flaw in the addPluginCapabilities() routine that automatically grants all Editor users a full set of manage_capabilities_* permissions, including the ability to create, rename, delete non-system roles, modify capabilities for any non-administrator role, restore role backups, and write arbitrary plugin options that start with cme_, capsman, pp_capabilities, or presspermit. Because this assignment occurs on the first admin_init after activation without any user confirmation, the rule is applied system-wide and the data is stored directly in the database. The resulting privilege escalation allows an attacker with Editor-level access to operate as a role manager, though it does not provide direct Administrator rights, since WordPress’s map_meta_cap still blocks the delegation of administrator-only permissions to other roles.

Affected Systems

Any WordPress installation that has the PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin installed with a version equal to or older than 2.50.0 is affected. The vulnerability exists across all operating systems and database backends supported by WordPress; the only requirement is that the plugin is active on a site where an authenticated Editor exists.

Risk and Exploitability

The CVSS score of 7.2 indicates a high potential impact, while the EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA KEV, but its exploitation would only require an authenticated user with Editor privileges; no remote code execution is necessary. Once an attacker has an Editor account, they can trigger the untrusted capability assignment by simply accessing any admin page after activating the plugin. The attack surface is therefore considered to be high for sites with editors who have not been subjected to additional monitoring or restrictions.

Generated by OpenCVE AI on September 9, 2026 at 10:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PublishPress Capabilities plugin to the latest version that removes or restricts the hard‑coded credential assignment for editors.
  • If an upgrade is not immediately possible, reset the database entries that grant manage_capabilities_* capability to editors by deleting the corresponding rows from the wp_options table or by running the plugin’s role‑reset function if available.
  • Re‑audit the existing role definitions on the site to ensure that no Editor role possesses excessive capabilities, and remove any superfluous capabilities that were granted by the vulnerable plugin.

Generated by OpenCVE AI on September 9, 2026 at 10:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Publishpress
Publishpress user Role Editor – Publishpress Capabilities: Access Control And User Roles
Wordpress
Wordpress wordpress
Vendors & Products Publishpress
Publishpress user Role Editor – Publishpress Capabilities: Access Control And User Roles
Wordpress
Wordpress wordpress

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities — including `manage_capabilities`, `manage_capabilities_roles`, `manage_capabilities_settings`, and `manage_capabilities_backup` — via a hard-coded `$eligible_roles = ['administrator', 'editor']` assignment that runs automatically on the first `admin_init` after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with `cme_`, `capsman`, `pp_capabilities`, or `presspermit` via `update_option()`. The escalation stops short of full Administrator access, as WordPress's `map_meta_cap` layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on `manage_capabilities_*` capabilities remains fully accessible.
Title PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Publishpress User Role Editor – Publishpress Capabilities: Access Control And User Roles
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-11T20:19:14.220Z

Reserved: 2026-08-18T15:39:14.778Z

Link: CVE-2026-75927

cve-icon Vulnrichment

Updated: 2026-09-11T20:13:39.295Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T08:17:21.997

Modified: 2026-09-11T21:17:15.663

Link: CVE-2026-75927

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:00Z

Weaknesses
  • CWE-269

    Improper Privilege Management