Sceawere

Vulnerability Detail

CVE-2026-48197UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

PublishPress Capabilities Privilege Escalation

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
16h ago
Vendor
PublishPress
Product
PublishPress Capabilities
Attack Type
Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-06T09:17:55.777Z",
  "pubdate": "2026-10-06T09:17:55.777Z",
  "executiveSummary": "The PublishPress Capabilities plugin (capability-manager-enhanced) is susceptible to an Incorrect Privilege Assignment vulnerability, which facilitates unauthorized privilege escalation.\nThis security flaw impacts versions ranging from n/a through 2.45.0.\nThe vulnerability arises from improper validation of user-supplied inputs when managing capabilities, allowing an attacker to modify or elevate their own permission level beyond intended restrictions.\nThe impact includes full compromise of administrative functions, as an attacker with lower-level access can promote their account to administrator status.\nThe threat is significant for WordPress environments where role-based access control is critical for site integrity.\nExploitation requires authenticated access to the target WordPress installation, though the level of initial authentication necessary is constrained by the plugin's interaction with the user management module.\nThe risk implication is a total loss of confidentiality, integrity, and availability of the affected WordPress site.",
  "technicalDetails": "The vulnerability resides within the permission management logic of the PublishPress Capabilities plugin, specifically affecting the way capabilities are assigned and updated within the WordPress database.\nThe root cause is an Incorrect Privilege Assignment, where the plugin fails to strictly validate or sanitize the request parameters when updating user capabilities. By manipulating the parameters sent to the plugin's capability-assignment functions, an authenticated user can inject arbitrary capabilities into their own user profile.\nThe attack flow initiates when an authenticated user performs a request intended to modify their role settings or capabilities. Due to the lack of adequate server-side checks, the application processes the malformed request as a legitimate administrative action. The plugin performs an unverified update to the 'wp_capabilities' metadata field associated with the attacker's user ID.\nBy specifically targeting the metadata update functions, an attacker can append the 'administrator' capability or other high-privilege permissions to their existing profile. This bypasses the built-in WordPress permission checks that should otherwise prevent non-administrative users from modifying sensitive security settings.\nThe vulnerable component is the internal capability management interface of PublishPress Capabilities, which is designed to provide granular control over roles but fails to enforce authorization checks on the requests that modify these roles. This lack of authorization allows an authenticated user to perform actions that should be restricted strictly to higher-privileged accounts.\nPost-exploitation, the attacker achieves full administrative control over the WordPress instance. This includes the ability to install malicious plugins, modify site content, alter database records, and execute arbitrary code via the theme or plugin editor. The exploitation occurs without requiring specialized network access, as the vulnerability is triggered through standard administrative interface requests that are handled insecurely by the plugin.\nBecause the plugin interacts directly with the WordPress user management subsystem, the escalated privileges are persistent and immediately recognized by the WordPress core authentication mechanisms. Once the 'wp_capabilities' field is modified, the attacker effectively bypasses the role-based access control (RBAC) model implemented by the site administrator."
}
CVE-2026-48197: PublishPress Capabilities Privilege Escalation (HIGH Severity, CVSS: 7.2) | Sceawere