PT-2026-94172 · WordPress · Puppyfw
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PuppyFW versions prior to 0.4.5
Description
Insufficient authorization on a REST route allows any authenticated user, including those with subscriber roles, to add, modify, or delete arbitrary blog options. This occurs because the plugin validates the caller against a capability provided within the request itself, which can be manipulated to achieve privilege escalation.
Recommendations
Update PuppyFW to version 0.4.5 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Puppyfw