cleantalk
Vulnerabilities and Security Researches

PublishPress Capabilities – User Role Editor, Access Permissions, Admin Menus, CVE-2026-32394

CVE, Research URL

CVE-2026-32394

Published on
Mar 14, 2026
Research Description
Missing Authorization vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Capabilities: from n/a through <= 2.31.0.
Affected versions
max 2.31.0.
Status
vulnerable