CVE-2026-88904 PUBLISHED

PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation

Assigner: WPScan
Reserved: 10.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.

Product Status

Vendor Unknown
Product PuppyFW
Versions Default: unknown
  • affected from 0 to 0.4.4 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE