Missing Authorization in WordPress - #VU151463

 

Missing Authorization in WordPress - #VU151463

Published: September 20, 2026


Vulnerability identifier: #VU151463
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to publish custom CSS without the edit_css capability.

The vulnerability exists due to improper authorization in the generic XML-RPC wp.newPost path when processing requests for caller-selected registered post types. A remote user can submit a raw customize_changeset post containing custom CSS to publish custom CSS without the edit_css capability.

The issue affects non-Super-Admin site administrators.


Affected software

WordPress

Remediation

Install security update from vendor's website.

WordPress - addressed in versions 4.7.36, 4.8.31, 4.9.32, 5.0.28, 5.1.25, 5.2.27, 5.3.24, 5.4.22, 5.5.21, 5.6.20, 5.7.18, 5.8.16, 5.9.17, 6.0.15, 6.1.13, 6.2.12, 6.3.11, 6.4.11, 6.5.11, 6.6.8, 6.7.8, 6.8.9, 6.9.8, 7.0.5, 7.1.1

External References

Related Security Bulletins