← Back to CVE List
CVE-2026-88904Wordfence
Vulnerability Summary
The PuppyFW plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.4.4. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with subscriber-level access and above, to elevate their privileges beyond those intended for their role.
CVSS v3.1 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- PuppyFW * - 0.4.4
Not provided by Wordfence for this CVE.