Description
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
Published: 2026-09-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The PuppyFW WordPress plugin up to version 0.4.4 lacks proper authorization on a REST route; it verifies the caller against a capability supplied in the request. This flaw (CWE-269) lets any authenticated user, including subscribers, add, modify, or delete arbitrary blog options, enabling them to elevate their privileges and potentially take full control of the site configuration.

Affected Systems

PuppyFW plugin versions 0.4.4 and earlier on WordPress installations.

Risk and Exploitability

With a CVSS score of 8.8, the vulnerability is considered high severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalogue. The attack vector is an authenticated, remote request to an unprotected REST endpoint. An attacker with subscriber-level access can exploit the flaw to modify site options, potentially granting themselves higher privileges or introducing malicious settings.

Generated by OpenCVE AI on September 18, 2026 at 02:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the PuppyFW plugin to a version newer than 0.4.4 or remove the plugin if it is not required.
  • If an upgrade is not possible, restrict the vulnerable REST route so that only users with administrator capability can access it, or disable the route entirely via plugin configuration or custom code.
  • Verify that users with non-administrative roles no longer possess the capability to modify options by reviewing role capabilities or using a role‑management plugin.

Generated by OpenCVE AI on September 18, 2026 at 02:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
Title PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:27:45.017Z

Reserved: 2026-09-10T12:18:40.284Z

Link: CVE-2026-88904

cve-icon Vulnrichment

Updated: 2026-09-17T12:11:00.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:52.203

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-88904

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:30:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management