Privilege Escalation in Simple User Capabilities Plugin for WordPress
CVE-2025-12158 
9.8CRITICAL
What is CVE-2025-12158?
The Simple User Capabilities plugin for WordPress is susceptible to a critical flaw allowing unauthenticated attackers to escalate user privileges. This vulnerability arises from a missing capability check in the suc_submit_capabilities() function, impacting all versions up to and including 1.0. Consequently, attackers can elevate the roles of any user account to that of an administrator, potentially leading to unauthorized access and control over the affected site.
Affected Version(s)
Simple User Capabilities * <= 1.0