Description
The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more permissive than necessary for Customizer-only demo access. This makes it possible for unauthenticated attackers to navigate beyond the Customizer and update arbitrary WordPress options such as `default_role`, leading to privilege escalation.
Published: 2026-07-08
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Backstage – Customizer Demo Access plugin grants the manage_options capability to the backstage_customizer_user demo role, a permission far more powerful than required for customizer‑only access. This over‑permissive role enables an unauthenticated attacker to change any thereby elevating privileges to full site administration.

Affected Systems

WordPress sites that have installed pixelgrade’s Backstage – Customizer Demo Access in version 1.4.2 or earlier are affected. Sites running newer versions or without the plugin are not impacted.

Risk and Exploitability

The plugin assigns manage_options capability to which could allow modification of WordPress options such as default_role. The CVSS score of 7.5 reflects a moderate‑to‑high risk level, while the EPSS score of < 1% indicates a low, but non‑zero, exploitation probability. This vulnerability is not listed in the CISA KEV catalog. The exact attack vector is not, so the ability to move beyond the Customizer and alter options is inferred from the description.

Generated by OpenCVE AI on July 29, 2026 at 14:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Backstage – Customizer Demo Access to the latest available version that addresses the issue
  • Disable the plugin entirely if an upgrade is not possible
  • Remove or modify the backstage_customizer_user role to eliminate the manage_options capability

Generated by OpenCVE AI on July 29, 2026 at 14:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Pixelgrade
Pixelgrade backstage – Customizer Demo Access
Wordpress
Wordpress wordpress
Vendors & Products Pixelgrade
Pixelgrade backstage – Customizer Demo Access
Wordpress
Wordpress wordpress

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Description The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more permissive than necessary for Customizer-only demo access. This makes it possible for unauthenticated attackers to navigate beyond the Customizer and update arbitrary WordPress options such as `default_role`, leading to privilege escalation.
Title Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Pixelgrade Backstage – Customizer Demo Access
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-08T13:01:09.142Z

Reserved: 2026-05-28T13:26:31.589Z

Link: CVE-2026-9842

cve-icon Vulnrichment

Updated: 2026-07-08T13:01:03.039Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T15:00:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management