Security Advisory

CVE-2025-12158

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-11-04 04:27:22
Last updated 2026-04-08 17:28:01
Assigner Wordfence
CVSS score 9.8
State PUBLISHED

Description

The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the suc_submit_capabilities() function in all versions up to, and including, 1.0. This makes it possible for unauthenticated attackers to elevate the role of any user account to administrator.