All verified exploits

CVE-2026-4314 Subscriber-to-Admin Privilege Escalation via Menu Editor Plugin

Deterministic high WordPress Added cve-verified-cve-2026-4314

Detects WordPress installs running the WP Extended plugin at version 3.2.4 or earlier. The Menu Editor module's grantVirtualCaps() method grants manage_options to any authenticated user when the URL contains '/wp-admin/profile.php' in the query string. A subscriber can escalate to administrator with a single crafted request, then create new admin accounts or install backdoors. Update WP Extended to 3.2.5 or later.

Related WordPress exploits

Is your app exploitable through CVE-2026-4314?

Scan your domain free