Impact
The PublishPress Capabilities plugin for WordPress contains a flaw in the addPluginCapabilities() routine that automatically grants all Editor users a full set of manage_capabilities_* permissions, including the ability to create, rename, delete non-system roles, modify capabilities for any non-administrator role, restore role backups, and write arbitrary plugin options that start with cme_, capsman, pp_capabilities, or presspermit. Because this assignment occurs on the first admin_init after activation without any user confirmation, the rule is applied system-wide and the data is stored directly in the database. The resulting privilege escalation allows an attacker with Editor-level access to operate as a role manager, though it does not provide direct Administrator rights, since WordPress’s map_meta_cap still blocks the delegation of administrator-only permissions to other roles.
Affected Systems
Any WordPress installation that has the PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin installed with a version equal to or older than 2.50.0 is affected. The vulnerability exists across all operating systems and database backends supported by WordPress; the only requirement is that the plugin is active on a site where an authenticated Editor exists.
Risk and Exploitability
The CVSS score of 7.2 indicates a high potential impact, while the EPSS score is not available, so the exact likelihood of exploitation is unknown. The vulnerability is not listed in CISA KEV, but its exploitation would only require an authenticated user with Editor privileges; no remote code execution is necessary. Once an attacker has an Editor account, they can trigger the untrusted capability assignment by simply accessing any admin page after activating the plugin. The attack surface is therefore considered to be high for sites with editors who have not been subjected to additional monitoring or restrictions.
OpenCVE Enrichment