WordPress Embedder Plugin Privilege Escalation Vulnerability
Vulnerability
A vulnerability in the Embedder plugin for WordPress, affecting versions 1.3 to 1.3.5, allows authenticated users with Subscriber-level access and above to arbitrarily modify site options. This issue arises from a lack of proper capability checks in the ajax_set_global_option() function, enabling potential privilege escalation by, for example, changing the default role for new users to administrator and granting admin access to the attacker.
Impact
Exploitation of this vulnerability could lead to unauthorized administrative access on the affected WordPress site.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.9remediation
0.0relevance
0.0threat
3.2urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
