PT-2026-56315 · WordPress · Backstage – Customizer Demo Access

·

CVE-2026-9842

·

Published

2026-07-08

·

Updated

2026-07-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Backstage - Customizer Demo Access versions prior to 1.4.3
Description This issue allows unauthenticated attackers to achieve privilege escalation. The plugin assigns the manage options capability to the backstage customizer user demo role, which provides permissions exceeding what is required for Customizer-only demo access. Consequently, attackers can navigate beyond the Customizer and modify arbitrary WordPress options, such as the default role variable.
Recommendations Update Backstage - Customizer Demo Access to a version newer than 1.4.2.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9842

Affected Products

Backstage – Customizer Demo Access