CVE-2026-77003: Content Mask 1.8.0 - 1.8.5.4 - Contributor Publish Capability Bypass via create_new_content_mask
Published Aug 23, 2026
·Updated
The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.
Affected Software
1 affected component
WordPress Content Mask<1.8.5.5
Event History
Aug 23, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
Description
Frequently Asked Questions
1
Which users can exploit this issue?
A user with a role as low as Contributor can exploit it. The affected plugin fails to verify the capability required to publish the post type being created.
2
What can an attacker do after exploiting it?
They can publish posts and pages without having the normal publish capability for those content types.
3
Which plugin versions are affected?
Content Mask versions before 1.8.5.5 are affected, including versions 1.8.0 through 1.8.5.4.