Impact
The Backstage – Customizer Demo Access plugin grants the manage_options capability to the backstage_customizer_user demo role, a permission far more powerful than required for customizer‑only access. This over‑permissive role enables an unauthenticated attacker to change any thereby elevating privileges to full site administration.
Affected Systems
WordPress sites that have installed pixelgrade’s Backstage – Customizer Demo Access in version 1.4.2 or earlier are affected. Sites running newer versions or without the plugin are not impacted.
Risk and Exploitability
The plugin assigns manage_options capability to which could allow modification of WordPress options such as default_role. The CVSS score of 7.5 reflects a moderate‑to‑high risk level, while the EPSS score of < 1% indicates a low, but non‑zero, exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The exact attack vector is not, so the ability to move beyond the Customizer and alter options is inferred from the description.
OpenCVE Enrichment