Skip to content
Noroxi

CWE-266 · 1,169 records

Incorrect Privilege Assignment

CVEs in this class

1,173 records

  • CVE-2026-48172
    70This week

    LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026.

    CriticalCVSS 10.0KEVWeaponizedEPSS 1%

    litespeedtech · litespeed cpanel pluginMay 20, 2026

  • WordPress LiteSpeed Cache plugin <= 6.3.0.1 - Unauthenticated Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    litespeedtech · litespeed cacheAug 21, 2024

  • WordPress SureTriggers <= 1.0.82 - Privilege Escalation Vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 54%

    brainstorm force · ottokitMay 1, 2025

  • WordPress Eventin plugin <= 4.0.26 - Privilege Escalation Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 28%

    themewinter · eventinMay 23, 2025

  • WordPress Modular DS plugin <= 2.5.1 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 22%

    modular ds · modular dsJan 14, 2026

  • Incorrect privilege assignment

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    grafana · grafanaNov 21, 2025

  • Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Interface Privilege Escalation Vulnerability

    HighCVSS 8.8No exploitEPSS 28%

    cisco · secure firewall threat defenseMay 3, 2022

  • WordPress Miraculous Core Plugin Plugin <= 2.0.7 - Privilege Escalation Vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 6%

    kamleshyadav · miraculous core pluginAug 28, 2025

  • WordPress LMS by Masteriyo plugin <= 1.7.2 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    themegrill · masteriyoMay 17, 2024

  • WordPress Wp NssUser Register plugin <= 1.0.0 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    saiful.total · wp nssuser registerDec 16, 2024

  • WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    rymera web co pty ltd. · woocommerce wholesale lead captureMar 19, 2026

  • WordPress Modular DS plugin <= 2.5.2 - Privilege Escalation vulnerability

    CriticalCVSS 10.0No exploitEPSS 1%

    Jan 16, 2026

  • Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a

    CriticalCVSS 10.0No exploitEPSS 0%

    upkeeper solutions · upkeeper instant privilege accessNov 20, 2024

  • Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows Privilege Escalation.This issue a

    CriticalCVSS 10.0No exploitEPSS 0%

    upkeeper solutions · upkeeper instant privilege accessNov 20, 2024

  • WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    hippoo · hippoo mobile app for woocommerceJun 11, 2026

  • A vulnerability has been identified in SINEMA Server (All versions < V14.0 SP2 Update 1).

    CriticalCVSS 9.9No exploitEPSS 1%

    siemens · sinema serverJan 16, 2020

  • WordPress WooCommerce - PDF Vouchers plugin < 4.9.9 - Broken Authentication vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    wpwebelite · woocommerce pdf vouchersDec 18, 2024

  • WordPress Exam Matrix plugin <= 1.5 - Privilege Escalation vulnerability

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    udit rawat · exam matrixOct 29, 2024

  • WordPress LiteSpeed Cache plugin <= 6.5.1 - Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    litespeedtech · litespeed cacheOct 29, 2024

  • CVE-2024-2409
    39Monitor

    MasterStudy LMS <= 3.3.1 - Unauthenticated Privilege Escalation via stm_lms_register AJAX Action

    CriticalCVSS 9.8No exploitEPSS 1%

    stylemixthemes · masterstudy lmsMar 29, 2024

  • CVE-2022-4272
    39Monitor

    FeMiner wms unrestricted upload

    CriticalCVSS 9.8No exploitEPSS 1%

    warehouse management system project · warehouse management systemDec 3, 2022

  • CVE-2022-4273
    39Monitor

    SourceCodester Human Resource Management System Content-Type employee.php unrestricted upload

    CriticalCVSS 9.8No exploitEPSS 1%

    oretnom23 · human resource management systemDec 3, 2022

  • WordPress Rankology SEO – On-site SEO plugin <= 2.2.4 - Privilege Escalation Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    rankology · rankology seo – on-site seoApr 11, 2025

  • Real Estate 7 WordPress <= 3.5.1 - Unauthenticated Privilege Escalation to Administrator

    CriticalCVSS 9.8No exploitEPSS 1%

    contempothemes · real estate 7Feb 12, 2025

  • WordPress VibeBP plugin <= 1.9.9.4.1 - Unauthenticated Privilege Escalation vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    vibethemes · vibebpDec 31, 2024

All vulnerability classes