CVE-2026-4297
newscred Welcome Software Publishing
The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via $wp_xmlrpc_server->login() (verifying credentials are valid) but does not perform any authorization check such as current_user_can('manage_options'). This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary WordPress options via XML-RP...
- CVSS
- 8.8
- EPSS
- 0.45% 36.9% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.24