The 多说社会化评论框 plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. The vulnerability exists due to a missing capability and nonce check on a directly web-accessible API endpoint, combined with a trivially forgeable HMAC-SHA1 signature keyed on an always-empty WordPress option, which allows the endpoint's `update_option` handler to pass attacker-controlled `option` and `value` parameters directly to WordPress's `update_option` function without any allowlist or sanitization. This makes it possible for unauthenticated attackers to update arbitrary WordPress options — such as setting `default_role` to `administrator` and enabling open registration — and subsequently register an account with full administrator privileges.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-08 05:16
Updated : 2026-07-08 14:55
NVD link : CVE-2026-14482
Mitre link : CVE-2026-14482
CVE.ORG link : CVE-2026-14482
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
