SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-13415

HIGH · CVSS 7.2 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The CMP WordPress plugin prior to version 4.1.18 is vulnerable due to a lack of an option-name allow-list during AJAX settings imports, enabling users with Editor roles to modify arbitrary WordPress options. This flaw can lead to privilege escalation, potentially allowing Editors to gain Administrator access. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this security risk.

CVE
CVE-2026-13415
Severity
HIGH
CVSS
7.2
EPSS
0.26%
WordPress

Original NVD Description

The CMP WordPress plugin before 4.1.18 does not enforce an option-name allow-list when importing settings via one of its AJAX actions, allowing users with the Editor role (when the administrator has granted the Editor role access to the CMP WordPress plugin before 4.1.18's admin-bar controls) to update arbitrary WordPress options, including options that lead to privilege escalation to Administrator.