PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise
60Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 6.6%
from disclosure to weapon576 days
Published on NVDJan 10
1st PoC+576d
VulnCheckDec 6
exploitation probability
6.6%top 7% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short
The PublishPress Capabilities plugin before version 2.3.1 allows anyone, even without logging in, to change important website settings like user roles through a missing security check. An attacker could make new users administrators and take over the blog.
Technical detail
An unauthenticated attacker can exploit a missing CSRF token validation and authorization check in the plugin's init hook to update arbitrary WordPress options via a crafted request. By modifying the default user role option, an attacker can escalate privileges of newly registered users to administrator, leading to complete blog compromise.
Summary generated and translated by AI from the official description.
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
Affected products
Unknown · PublishPress Capabilities ProUnknown · PublishPress Capabilities – User Role Access, Editor Permissions, Admin Menuspublic PoCs found — 1
vulncheckvulncheck.com/xdb/d2073fd30796unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.