VYPR

Backstage

by WordPress

CVEs (1)

  • CVE-2026-9842Jul 8, 2026
    risk 0.00cvss epss 0.00

    The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more…