CVE-2026-88904: PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit the vulnerable REST route, including users with the Subscriber role. An attacker does not need administrative privileges before exploiting it.
What access does an attacker need?
The attacker needs a valid authenticated WordPress account. The issue is exposed through a PuppyFW REST route whose authorization check uses a capability supplied in the request.
What could exploitation allow?
An attacker can add, change, or delete arbitrary WordPress blog options. This can be used to escalate privileges.
Which PuppyFW versions are affected?
PuppyFW versions through 0.4.4 are affected.