The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.
CVE-2026-77003
NONE
EPSS 0.18%
Updated Aug 23, 2026
WordPress
unknown:content mask
CVE Details
CVE ID
CVE-2026-77003
Published Date
Aug 23, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.18%
Likelihood of exploitation in next 30 days
Percentile:
7.9th percentile (higher than 7.9% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory