Executive brief
A WordPress plugin used to provide demo access to site customization features contains a security flaw that allows unauthorized users to gain administrative control. By exploiting overly broad permissions granted to the demo role, an attacker can change core website settings, such as the default role for new users. This could lead to a full takeover of the website, resulting in data theft or site defacement.
Technical details
The vulnerability is a privilege escalation flaw caused by the plugin incorrectly assigning the 'manage_options' capability to the 'backstage_customizer_user' demo role. While intended only for Customizer access, this capability allows users to modify global WordPress settings. An unauthenticated attacker can exploit this to update arbitrary options, such as 'default_role' or 'users_can_register', effectively allowing them to create new administrator accounts or elevate existing ones. The issue exists in all versions up to 1.4.2.
Affected products
- The Backstage Backstage - Customizer Demo Access up to, and including, 1.4.2
Timeline
- 2026-07-08: disclosed