Impact
The Add User Autocomplete WordPress plugin does not perform capability or nonce checks when creating a pending site‑membership invitation that carries a caller‑supplied role. This flaw allows any authenticated user to request an invitation that grants themselves administrator privileges on a WordPress multisite, which constitutes improper privilege management (CWE‑269).
Affected Systems
WordPress installations running Add User Autocomplete before version 1.2, on a multisite network, are affected. The issue applies to any authenticated user in the network, including subscribers, and it is independent of other themes or plugins.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is below 1 %, suggesting a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because the flaw can be triggered by any valid user on a multisite site, the potential impact remains high: to administrator, then gain full control of the network, alter settings, and deploy malicious plugins.
OpenCVE Enrichment