CWE-266 · 1,169 records
Incorrect Privilege Assignment
CVEs in this class
1,173 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
70This week | CVE-2026-48172Weaponized | LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.litespeedtech · litespeed cpanel plugin · CWE-266 | Critical10.0 | KEV | 1.0% | May 20, 2026 |
59Plan | CVE-2024-28000Proof of concept | WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Critical9.8 | — | 68.3% | Aug 21, 2024 |
55Plan | CVE-2025-27007Weaponized | WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerabilitybrainstorm force · ottokit · CWE-266 | Critical9.8 | — | 53.9% | May 1, 2025 |
47Plan | CVE-2025-47539Proof of concept | WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerabilitythemewinter · eventin · CWE-266 | Critical9.8 | — | 27.9% | May 23, 2025 |
46Plan | CVE-2026-23550Proof of concept | WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerabilitymodular ds · modular ds · CWE-266 | Critical9.8 | — | 21.7% | Jan 14, 2026 |
44Plan | CVE-2025-41115Proof of concept | Incorrect privilege assignmentgrafana · grafana · CWE-266 | Critical9.8 | — | 16.9% | Nov 21, 2025 |
43Plan | CVE-2022-20759No exploit | Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerabilitycisco · secure firewall threat defense · CWE-266 | High8.8 | — | 28.2% | May 3, 2022 |
41Plan | CVE-2025-49388Proof of concept | WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerabilitykamleshyadav · miraculous core plugin · CWE-266 | Critical9.8 | — | 5.7% | Aug 28, 2025 |
40Plan | CVE-2024-24882Proof of concept | WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerabilitythemegrill · masteriyo · CWE-266 | Critical9.8 | — | 2.1% | May 17, 2024 |
40Plan | CVE-2024-54363Proof of concept | WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerabilitysaiful.total · wp nssuser register · CWE-266 | Critical9.8 | — | 1.9% | Dec 16, 2024 |
40Plan | CVE-2026-27542Proof of concept | WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerabilityrymera web co pty ltd. · woocommerce wholesale lead capture · CWE-266 | Critical9.8 | — | 1.8% | Mar 19, 2026 |
40Plan | CVE-2026-23800No exploit | WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerabilityCWE-266 | Critical10.0 | — | 0.5% | Jan 16, 2026 |
40Plan | CVE-2024-9478No exploit | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue aupkeeper solutions · upkeeper instant privilege access · CWE-266 | Critical10.0 | — | 0.4% | Nov 20, 2024 |
40Plan | CVE-2024-9479No exploit | Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue aupkeeper solutions · upkeeper instant privilege access · CWE-266 | Critical10.0 | — | 0.4% | Nov 20, 2024 |
39Monitor | CVE-2026-49060Proof of concept | WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerabilityhippoo · hippoo mobile app for woocommerce · CWE-266 | Critical9.8 | — | 1.6% | Jun 11, 2026 |
39Monitor | CVE-2019-10940No exploit | A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).siemens · sinema server · CWE-266 | Critical9.9 | — | 1.2% | Jan 16, 2020 |
39Monitor | CVE-2024-54383Proof of concept | WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerabilitywpwebelite · woocommerce pdf vouchers · CWE-266 | Critical9.8 | — | 1.2% | Dec 18, 2024 |
39Monitor | CVE-2024-50485Proof of concept | WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerabilityudit rawat · exam matrix · CWE-266 | Critical9.8 | — | 1.0% | Oct 29, 2024 |
39Monitor | CVE-2024-50550No exploit | WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerabilitylitespeedtech · litespeed cache · CWE-266 | Critical9.8 | — | 0.9% | Oct 29, 2024 |
39Monitor | CVE-2024-2409No exploit | MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Actionstylemixthemes · masterstudy lms · CWE-266 | Critical9.8 | — | 0.8% | Mar 29, 2024 |
39Monitor | CVE-2022-4272No exploit | FeMiner wms unrestricted uploadwarehouse management system project · warehouse management system · CWE-266 | Critical9.8 | — | 0.8% | Dec 3, 2022 |
39Monitor | CVE-2022-4273No exploit | SourceCodester Human Resource Management System Content-Type employee.php unrestricted uploadoretnom23 · human resource management system · CWE-266 | Critical9.8 | — | 0.8% | Dec 3, 2022 |
39Monitor | CVE-2025-32491No exploit | WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerabilityrankology · rankology seo – on-site seo · CWE-266 | Critical9.8 | — | 0.8% | Apr 11, 2025 |
39Monitor | CVE-2024-13421No exploit | Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administratorcontempothemes · real estate 7 · CWE-266 | Critical9.8 | — | 0.8% | Feb 12, 2025 |
39Monitor | CVE-2024-56040No exploit | WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerabilityvibethemes · vibebp · CWE-266 | Critical9.8 | — | 0.8% | Dec 31, 2024 |
- CVE-2026-4817270This week
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.
CriticalCVSS 10.0KEVWeaponizedEPSS 1%litespeedtech · litespeed cpanel pluginMay 20, 2026
- CVE-2024-2800059Plan
WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 68%litespeedtech · litespeed cacheAug 21, 2024
- CVE-2025-2700755Plan
WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 54%brainstorm force · ottokitMay 1, 2025
- CVE-2025-4753947Plan
WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 28%themewinter · eventinMay 23, 2025
- CVE-2026-2355046Plan
WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 22%modular ds · modular dsJan 14, 2026
- CVE-2025-4111544Plan
Incorrect privilege assignment
CriticalCVSS 9.8Proof of conceptEPSS 17%grafana · grafanaNov 21, 2025
- CVE-2022-2075943Plan
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability
HighCVSS 8.8No exploitEPSS 28%cisco · secure firewall threat defenseMay 3, 2022
- CVE-2025-4938841Plan
WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 6%kamleshyadav · miraculous core pluginAug 28, 2025
- CVE-2024-2488240Plan
WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%themegrill · masteriyoMay 17, 2024
- CVE-2024-5436340Plan
WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%saiful.total · wp nssuser registerDec 16, 2024
- CVE-2026-2754240Plan
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%rymera web co pty ltd. · woocommerce wholesale lead captureMar 19, 2026
- CVE-2026-2380040Plan
WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability
CriticalCVSS 10.0No exploitEPSS 1%Jan 16, 2026
- CVE-2024-947840Plan
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a
CriticalCVSS 10.0No exploitEPSS 0%upkeeper solutions · upkeeper instant privilege accessNov 20, 2024
- CVE-2024-947940Plan
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a
CriticalCVSS 10.0No exploitEPSS 0%upkeeper solutions · upkeeper instant privilege accessNov 20, 2024
- CVE-2026-4906039Monitor
WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 2%hippoo · hippoo mobile app for woocommerceJun 11, 2026
- CVE-2019-1094039Monitor
A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).
CriticalCVSS 9.9No exploitEPSS 1%siemens · sinema serverJan 16, 2020
- CVE-2024-5438339Monitor
WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 1%wpwebelite · woocommerce pdf vouchersDec 18, 2024
- CVE-2024-5048539Monitor
WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerability
CriticalCVSS 9.8Proof of conceptEPSS 1%udit rawat · exam matrixOct 29, 2024
- CVE-2024-5055039Monitor
WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%litespeedtech · litespeed cacheOct 29, 2024
- CVE-2024-240939Monitor
MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action
CriticalCVSS 9.8No exploitEPSS 1%stylemixthemes · masterstudy lmsMar 29, 2024
- CVE-2022-427239Monitor
FeMiner wms unrestricted upload
CriticalCVSS 9.8No exploitEPSS 1%warehouse management system project · warehouse management systemDec 3, 2022
- CVE-2022-427339Monitor
SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload
CriticalCVSS 9.8No exploitEPSS 1%oretnom23 · human resource management systemDec 3, 2022
- CVE-2025-3249139Monitor
WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerability
CriticalCVSS 9.8No exploitEPSS 1%rankology · rankology seo – on-site seoApr 11, 2025
- CVE-2024-1342139Monitor
Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator
CriticalCVSS 9.8No exploitEPSS 1%contempothemes · real estate 7Feb 12, 2025
- CVE-2024-5604039Monitor
WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerability
CriticalCVSS 9.8No exploitEPSS 1%vibethemes · vibebpDec 31, 2024