CVE-2026-88904
PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privilege Escalation
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the caller against a capability taken from the request itself, allowing any authenticated user, including subscribers, to add, modify and delete arbitrary blog options and thereby escalate their privileges.
| Vendor | unknown |
| Product | puppyfw |
| Published | Sep 17, 2026 |
| Last Updated | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown puppyfw
Be the first to know when new high vulnerabilities affecting unknown puppyfw are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / PuppyFW
0 โค 0.4.4
References
Credits
Naoki Kawahigashi WPScan