Known CVE
PublishPress Capabilities < 2.3.1 - Missing Authorization
The PublishPress Capabilities plugin for WordPress before 2.3.1 does not have proper authorization and CSRF checks when updating settings via the init hook, allowing unauthenticated attackers to update arbitrary blog options, such as setting the default role to administrator.
CVE-2021-25032
Critical2021CVSS 9.8CWE-352
wpscan · cve2021 · wordpress · wp-plugin · wp · capability-manager-enhanced · authenticated · vkev
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website