Junglewise Threat Intelligence

CVE-2026-57692: LCweb PrivateContent privilege escalation

CVE-2026-57692 · Severity: critical · CVSS 9.8 · Published 2026-07-01

Executive brief

LCweb PrivateContent, a WordPress plugin used to manage restricted site content and user memberships, contains a critical security flaw. This vulnerability allows an unauthorized person to gain administrative control over the website. Once exploited, an attacker could access sensitive customer data, modify site content, or completely lock out the legitimate owners.

Technical details

The LCweb PrivateContent plugin for WordPress (up to and including version 9.9.2) suffers from an Incorrect Privilege Assignment vulnerability (CWE-266). The flaw allows an unauthenticated remote attacker to escalate their privileges, potentially gaining full administrative access to the WordPress environment. The attack vector is network-based with low complexity and requires no user interaction. As of the advisory date, no official patch has been released by the vendor, though third-party mitigation rules are available.

Affected products

  • LCweb PrivateContent n/a through 9.9.2

Timeline

  • 2026-07-01: disclosed: Reported by 0xd4rk5id3 via Patchstack
  • 2026-07-01: advisory: Published by Patchstack and NVD

References