CVE-2026-94487: WordPress PublishPress Capabilities plugin <= 2.50.1 - Cross Site Request Forgery (CSRF) vulnerability
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress PublishPress Capabilities pluginto a version that resolves this vulnerability.Fixed in 2.51.0
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker does not need to authenticate to the affected site, but exploitation requires a user to interact with a crafted request, as indicated by the UI:R vector.
Which installations are known to be affected?
PublishPress Capabilities versions 2.50.1 and earlier are identified as affected. The provided data does not state whether particular plugin settings or deployment configurations change exposure.
What is the potential impact if exploitation succeeds?
The vulnerability is rated high with a CVSS score of 8.1 and indicates high impact to integrity and availability. No confidentiality impact is listed.