Arbitrary Option Modification Vulnerability in Welcome Software Publishing Plugin for WordPress
CVE-2026-4297
8.8HIGH
What is CVE-2026-4297?
The Welcome Software Publishing plugin for WordPress contains an Arbitrary Options Update vulnerability that allows authenticated users with Subscriber-level access and above to modify WordPress options through the XML-RPC interface. This issue stems from the absence of a capability check within the nc_setOption() function, subsequently exposed by the nc.setOption XML-RPC method. While user authentication is performed, the lack of proper authorization permits unauthorized updates, including the ability to escalate a user's privileges by changing settings such as 'default_role' to 'administrator', potentially leading to complete site takeover.
Affected Version(s)
Welcome Software Publishing 0 <= 0.0.31