PT-2022-9589 · Publishpress · Publishpress Capabilities Pro

Krzysztof Zając

·

Published

2022-01-10

·

Updated

2025-06-05

·

CVE-2021-25032

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PublishPress Capabilities WordPress plugin versions prior to 2.3.1 PublishPress Capabilities Pro WordPress plugin versions prior to 2.3.1
Description The issue concerns a lack of authorization and CSRF checks when updating plugin settings via the init hook. This allows unauthenticated attackers to update arbitrary blog options, such as the default role, potentially making any new registered user an administrator.
Recommendations For PublishPress Capabilities WordPress plugin versions prior to 2.3.1, update to version 2.3.1 or later. For PublishPress Capabilities Pro WordPress plugin versions prior to 2.3.1, update to version 2.3.1 or later.

Exploit

Fix

Missing Authorization

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25032

Affected Products

Publishpress Capabilities Pro