PT-2026-88888 · Publishpress · User Role Editor – Publishpress Capabilities: Access Control/User Roles

·

CVE-2026-75927

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the addPluginCapabilities() function unconditionally granting the Editor role all 15 manage capabilities * capabilities — including manage capabilities, manage capabilities roles, manage capabilities settings, and manage capabilities backup — via a hard-coded $eligible roles = ['administrator', 'editor'] assignment that runs automatically on the first admin init after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with cme , capsman, pp capabilities, or presspermit via update option(). The escalation stops short of full Administrator access, as WordPress's map meta cap layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on manage capabilities * capabilities remains fully accessible.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75927

Affected Products

User Role Editor – Publishpress Capabilities: Access Control/User Roles