Junglewise Threat Intelligence

CVE-2026-14482: Duoshuo Social Comment Box WordPress plugin privilege escalation

CVE-2026-14482 · Severity: high · CVSS 8.8 · Published 2026-07-08

Executive brief

A popular WordPress social commenting plugin contains a critical security flaw that allows unauthorized users to gain full administrative control over a website. By exploiting a weakness in how the plugin handles settings updates, an attacker can change site configurations to grant themselves administrator privileges. This could lead to a complete site takeover, data theft, or the installation of malicious software.

Technical details

The vulnerability stems from a missing capability check and nonce validation on a directly web-accessible API endpoint within the plugin. The endpoint uses an HMAC-SHA1 signature for authentication, but because the secret key is derived from a WordPress option that is typically empty, the signature is trivially forgeable. An attacker can exploit the `update_option` handler to pass arbitrary `option` and `value` parameters to the core WordPress `update_option` function. By modifying critical options such as 'default_role' to 'administrator' and enabling 'users_can_register', an unauthenticated attacker can register a new account and immediately escalate their privileges to site administrator.

Affected products

  • shen2 多说社会化评论框 (Duoshuo Social Comment Box) <= 1.2

Timeline

  • 2026-07-08: disclosed: CVE-2026-14482 published

References