
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4261 is a privilege escalation vulnerability in the Expire Users plugin for WordPress, affecting all versions up to and including 1.2.2. The flaw allows authenticated attackers with Subscriber-level access or higher to elevate their privileges to administrator level by manipulating the on_expire_default_to_role user meta field via the save_extra_user_profile_fields function without proper authorization checks. It was published on March 21, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 8.8 (High) (Wordfence, Feedly).
The root cause is classified as CWE-862 (Missing Authorization), with an estimated secondary classification of CWE-269 (Improper Privilege Management). The save_extra_user_profile_fields function in the plugin's admin component (admin/expire-user.php, line 163) fails to validate whether the requesting user is authorized to modify the on_expire_default_to_role user meta field. An authenticated attacker with a Subscriber account can submit a crafted HTTP POST request to their own profile update endpoint, setting this meta value to administrator, which is then applied when their account expires or is processed by the plugin. No special configuration or user interaction is required beyond having a valid low-privilege account (Wordfence, Plugin Source).
Successful exploitation grants a low-privileged subscriber full administrative control over the WordPress installation. An attacker with administrator access can modify site content, install or activate malicious plugins or themes, create additional backdoor accounts, access sensitive user data, and fully compromise the website and its underlying server environment. The impact spans confidentiality, integrity, and availability — all rated High — and could facilitate further lateral movement within hosted environments or supply-chain attacks against site visitors (Wordfence, Feedly).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.039%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The vulnerability is detectable by Qualys (detection ID 531139) (Feedly, Qualys).
/wp-content/plugins/expire-users/readme.txt or using tools like WPScan.wp-admin/profile.php or the REST API equivalent), including the parameter on_expire_default_to_role=administrator in the request body.save_extra_user_profile_fields function processes the submitted field without authorization checks, updating the attacker's on_expire_default_to_role user meta to administrator.wp-admin/profile.php or profile update endpoints from Subscriber-level accounts, particularly with unexpected parameters such as on_expire_default_to_role.wp_usermeta table where meta_key = 'on_expire_default_to_role' and meta_value = 'administrator' for non-admin users.administrator role without administrative action; review wp_usermeta and wp_users for anomalous role assignments.As of the disclosure date, no patched version of the Expire Users plugin is available. The recommended immediate action is to deactivate and remove the Expire Users plugin (versions ≤ 1.2.2) from all WordPress installations. Administrators should audit all user accounts for unauthorized privilege escalations by reviewing the wp_usermeta table for suspicious on_expire_default_to_role values and checking for unexpected administrator accounts. Consider using an alternative, actively maintained WordPress plugin for user expiration management. Monitor for a patched release from the plugin vendor (husobj) before reinstalling (Wordfence, Feedly).
Wordfence included CVE-2026-4261 in their weekly WordPress vulnerability report for the period of March 16–22, 2026, highlighting it as a notable privilege escalation issue (Wordfence Blog). The vulnerability received automated social media coverage via security-focused Mastodon and Bluesky accounts, and was picked up by aggregators including RedPacket Security and CVEFeed. Community reaction has been moderate, consistent with a plugin-level WordPress vulnerability without an available patch.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."