Impact
An unauthenticated Cross Site Request Forgery vulnerability exists in the WordPress PublishPress Capabilities plugin versions up to and including 2.50.1. The flaw allows a forged request without authentication, enabling an attacker to perform privileged operations that normally require authorisation. This can lead to unauthorized modification of user roles, capability definitions, or the overall permission structure within the WordPress site, effectively escalating the attacker’s privileges.
Affected Systems
PublishPress: PublishPress Capabilities plugin for WordPress is affected. All versions of the plugin up to and including 2.50.1 are vulnerable. Deployments of WordPress sites that rely on this plugin before version 2.51.0 are at risk.
Risk and Exploitability
The CVSS score of 8.1 classifies this flaw as high severity. An attacker can exploit it without any authentication by sending a malicious request from any origin. Although the EPSS score is not available and the vulnerability is not listed in CISA KEV, the lack of authentication barriers and the potential for privilege escalation elevate the risk; site administrators should treat this promptly.
OpenCVE Enrichment