Wordpress Alert: Contributor-to-editor privilege escalation
A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.
What it looks like
A contributor gains an editor-only action through a plugin or custom route.
Why it matters
The user may publish or alter content beyond their assigned role.
What to check
Check capability enforcement on publishing and role-management actions.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Access Control