Executive brief
PublishPress Permissions is a WordPress plugin that manages access permissions and user roles on publishing workflows. An unauthenticated attacker can manipulate object IDs in URLs to view or access data belonging to other users, potentially exposing confidential editorial content, user profiles, or permission settings without proper authorization checks.
Technical details
The vulnerability is an Insecure Direct Object Reference (IDOR) flaw in PublishPress Permissions versions up to 4.8.3, where insufficient access control on object IDs allows unauthenticated users to directly reference and access resources they should not have permission to view. The vulnerability results from inadequate authorization checks when processing object identifiers in requests. An attacker can manipulate IDs in URLs or API calls to bypass access controls and retrieve arbitrary user data, editorial content, or permission metadata. The issue requires no authentication and is exploitable over the network. A patch is available in version 4.8.4 and later.
Affected products
- PublishPress Permissions <=4.8.3
Timeline
- 2026-09-02: disclosed: Vulnerability disclosed publicly by Patchstack