Executive brief
A popular WordPress social commenting plugin contains a critical security flaw that allows unauthorized users to gain full administrative control over a website. By exploiting a weakness in how the plugin handles settings updates, an attacker can change site configurations to grant themselves administrator privileges. This could lead to a complete site takeover, data theft, or the installation of malicious software.
Technical details
The vulnerability stems from a missing capability check and nonce validation on a directly web-accessible API endpoint within the plugin. The endpoint uses an HMAC-SHA1 signature for authentication, but because the secret key is derived from a WordPress option that is typically empty, the signature is trivially forgeable. An attacker can exploit the `update_option` handler to pass arbitrary `option` and `value` parameters to the core WordPress `update_option` function. By modifying critical options such as 'default_role' to 'administrator' and enabling 'users_can_register', an unauthenticated attacker can register a new account and immediately escalate their privileges to site administrator.
Affected products
- shen2 多说社会化评论框 (Duoshuo Social Comment Box) <= 1.2
Timeline
- 2026-07-08: disclosed: CVE-2026-14482 published
References
- https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/LocalServer.php
- https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/LocalServer.php
- https://plugins.trac.wordpress.org/browser/duoshuo/tags/1.2/api.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/732c7ccd-de50-4e27-8cb9-3bb0ed30f0b4?source=cve