EIP-2026-114158
PRE-CVEWordPress Plugin User Meta Manager 3.4.6 - Privilege Escalation
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114158. PoCs published by Panagiotis Vagenas.
AI-analyzed exploit summary This exploit demonstrates a privilege escalation vulnerability in the WordPress User Meta Manager plugin (v3.4.6). A registered user can modify the `wp_capabilities` meta field of any user, including their own, to escalate to an administrator role via a crafted AJAX request.
Description
WordPress Plugin User Meta Manager 3.4.6 - Privilege Escalation
Exploits (1)
This exploit demonstrates a privilege escalation vulnerability in the WordPress User Meta Manager plugin (v3.4.6). A registered user can modify the `wp_capabilities` meta field of any user, including their own, to escalate to an administrator role via a crafted AJAX request.