CVE-2026-75927: PublishPress Capabilities <= 2.50.0 - Authenticated (Editor+) Privilege Escalation to Fresh-Install Default Capability Grant

Published Sep 9, 2026
·
Updated

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the addPluginCapabilities() function unconditionally granting the Editor role all 15 managecapabilities capabilities — including managecapabilities, managecapabilitiesroles, managecapabilitiessettings, and managecapabilitiesbackup — via a hard-coded $eligibleroles = ['administrator', 'editor'] assignment that runs automatically on the first admininit after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with cme, capsman, ppcapabilities, or presspermit via updateoption(). The escalation stops short of full Administrator access, as WordPress's mapmetacap layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on managecapabilities capabilities remains fully accessible.

Affected Software

1 affected component
PublishPress PublishPress Capabilities<=2.50.0

Event History

Sep 9, 2026
CVE Published
via MITRE·07:40 AM
Data Sourced
via MITRE·07:40 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to this issue?

Sites running PublishPress Capabilities versions up to and including 2.50.0 are affected. Exploitation requires an authenticated user with the WordPress Editor role.

2

Is a non-default configuration or administrator action required for the capability grant?

No. On the first admin_init event after plugin activation, the plugin automatically treats both Administrator and Editor as eligible roles and grants the capabilities without administrator opt-in.

3

Does an Editor become a full WordPress Administrator?

No. The described escalation does not provide full Administrator access because WordPress map_meta_cap restrictions still apply. However, the Editor can manage non-administrator roles and capabilities, restore role backups, and modify certain plugin options.

4

What evidence could indicate that the grants have already been applied?

The capability grants persist directly in the database after the post-activation admin_init event. An affected site may show the Editor role holding manage_capabilities_* permissions, including manage_capabilities, manage_capabilities_roles, manage_capabilities_settings, and manage_capabilities_backup.

5

What option changes can an escalated Editor make?

They can write arbitrary plugin options through update_option() when the option name begins with cme_, capsman, pp_capabilities, or presspermit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203