
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12158 is a critical privilege escalation vulnerability in the Simple User Capabilities plugin for WordPress, caused by a missing capability check on the suc_submit_capabilities() function. It affects all versions of the plugin up to and including version 1.0, allowing unauthenticated remote attackers to elevate any user account to administrator. The vulnerability was published on November 4, 2025, and was reported by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, NVD).
The root cause is CWE-862 (Missing Authorization): the suc_submit_capabilities() function in the plugin's user_access.php file does not perform any capability or authentication check before processing role-change requests (NVD, Wordfence). Because no nonce verification or privilege check is enforced, any unauthenticated HTTP request can invoke this function and assign administrator-level roles to arbitrary user accounts. The attack vector is network-based, requires no authentication, no user interaction, and low complexity, making it trivially exploitable against any WordPress site running the affected plugin version (ZeroPath).
Successful exploitation grants an unauthenticated attacker full administrative control over the affected WordPress site. This enables complete site compromise, including modification or deletion of content, installation of malicious plugins or backdoors, theft of sensitive user data, and site defacement. The attacker can also leverage administrator access for lateral movement within the hosting environment or to establish persistent access (Wordfence, Avertium).
As of the time of reporting, no public proof-of-concept exploit code has been confirmed, and there is no evidence of active in-the-wild exploitation (Feedly). The EPSS score is approximately 0.052%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the critical CVSS score and zero-authentication requirement make it a high-priority target if exploitation tooling is developed (Wordfence).
/wp-content/plugins/simple-user-capabilities/./wp-json/wp/v2/users) or login page enumeration to identify existing user account IDs or usernames on the target site.wp-admin/admin-ajax.php or the relevant action hook) invoking the suc_submit_capabilities() function, specifying a target user ID and the desired role (e.g., administrator).wp-admin/admin-ajax.php with actions related to suc_submit_capabilities; unexpected role-change entries in the WordPress database audit trail.wp-content/ directory.Administrators should immediately update the Simple User Capabilities plugin beyond version 1.0 to a patched release if available, or disable and remove the plugin entirely until a fix is confirmed (Wordfence, Avertium). All WordPress user accounts should be audited immediately for unauthorized privilege changes, and any suspicious administrator accounts should be removed. Implementing a web application firewall (WAF) — such as Wordfence — can help block exploitation attempts while a patch is applied.
Wordfence published the vulnerability in their threat intelligence database and included it in their weekly WordPress vulnerability report for November 3–9, 2025 (Wordfence Blog). Avertium issued a flash notice highlighting the critical nature of the flaw and recommending immediate remediation (Avertium). Community aggregators including VulnDB, CIRCL, and CVEFeed.io tracked the disclosure, and ZeroPath published a dedicated technical blog post shortly after the CVE was published (ZeroPath).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."