Skip to content

Known CVE

PublishPress Capabilities < 2.3.1 - Missing Authorization

The PublishPress Capabilities plugin for WordPress before 2.3.1 does not have proper authorization and CSRF checks when updating settings via the init hook, allowing unauthenticated attackers to update arbitrary blog options, such as setting the default role to administrator.

CVE-2021-25032

Critical2021CVSS 9.8CWE-352

wpscan · cve2021 · wordpress · wp-plugin · wp · capability-manager-enhanced · authenticated · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website