← back
CVE-2021-25032observed exploitationCWE-352CWE-862

PublishPress Capabilities < 2.3.1 - Unauthenticated Arbitrary Options Update to Blog Compromise

60Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 6.6%
from disclosure to weapon576 days
Published on NVDJan 10
1st PoC+576d
VulnCheckDec 6
exploitation probability
6.6%top 7% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
In short

The PublishPress Capabilities plugin before version 2.3.1 allows anyone, even without logging in, to change important website settings like user roles through a missing security check. An attacker could make new users administrators and take over the blog.

Technical detail

An unauthenticated attacker can exploit a missing CSRF token validation and authorization check in the plugin's init hook to update arbitrary WordPress options via a crafted request. By modifying the default user role option, an attacker can escalate privileges of newly registered users to administrator, leading to complete blog compromise.

Summary generated and translated by AI from the official description.
The PublishPress Capabilities WordPress plugin before 2.3.1, PublishPress Capabilities Pro WordPress plugin before 2.3.1 does not have authorisation and CSRF checks when updating the plugin's settings via the init hook, and does not ensure that the options to be updated belong to the plugin. As a result, unauthenticated attackers could update arbitrary blog options, such as the default role and make any new registered user with an administrator role.
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.