๐Ÿ” CVE Alert

CVE-2026-88904

HIGH 8.8

PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.

Vendor unknown
Product puppyfw
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for unknown puppyfw

Be the first to know when new high vulnerabilities affecting unknown puppyfw are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / PuppyFW
0 โ‰ค 0.4.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d65eff64-0c20-4cfe-8ba2-1d202a5e4306/

Credits

Naoki Kawahigashi WPScan