Privilege Escalation in CouponXxL Custom Post Types by Pebas
CVE-2025-52726

8.6HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 June 2025

What is CVE-2025-52726?

An Incorrect Privilege Assignment vulnerability exists in Pebas CouponXxL Custom Post Types, enabling potential privilege escalation. This flaw allows users to exploit the design of the system, gaining elevated permissions that should not be accessible to them. The affected versions span from n/a up to 3.0, making it critical for users to update to avoid unauthorized access and maintain the integrity of their application.

Affected Version(s)

CouponXxL Custom Post Types <= 3.0

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds (Patchstack Alliance)
.
CVE-2025-52726 : Privilege Escalation in CouponXxL Custom Post Types by Pebas