Missing Authorization in WordPress - #VU151463
Published: September 20, 2026
Vulnerability details
The vulnerability allows a remote user to publish custom CSS without the edit_css capability.
The vulnerability exists due to improper authorization in the generic XML-RPC wp.newPost path when processing requests for caller-selected registered post types. A remote user can submit a raw customize_changeset post containing custom CSS to publish custom CSS without the edit_css capability.
The issue affects non-Super-Admin site administrators.