VYPR

Backstage - Customizer Demo Access

by WordPress

CVEs (1)

  • CVE-2026-9842HigJul 8, 2026
    risk 0.00cvss 7.5epss 0.00

    The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more…