CVE-2026-77003

Published Aug 23, 2026

Last updated 18 hours ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-77003 is a vulnerability identified in the Content Mask WordPress plugin, affecting versions prior to 1.8.5.5. This flaw stems from the plugin's failure to adequately verify the required capabilities for publishing post types. Consequently, users with a Contributor role, which typically has limited publishing permissions, are able to publish posts and pages on a WordPress site without possessing the explicit publish capability.

Description
The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.
Source
contact@wpscan.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Secondary
Base score
2.7
Impact score
1.4
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Severity
LOW

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-269

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

3

References

Sources include official advisories and independent security research.