Medium 4.3
2026-03-13< 2.32.0
CVE-2026-32394
Minimum safe version
2.32.0
Update to 2.32.0 or later to address 8 fixable vulnerabilities
CVE-2026-32394
WordPress PublishPress Capabilities Plugin <= 2.3.2 is vulnerable to Cross Site Scripting (XSS)
PublishPress Capabilities <= 1.5.8 - Authenticated SQL Injection
PublishPress Capabilities <= 2.3.2 - Reflected Cross-Site Scripting
Capability Manager Enhanced <= 1.5.8 - Authenticated SQLi
PublishPress Capabilities < 2.3.3 - Reflected Cross-Site Scripting
CVE-2022-3366
CVE-2021-25032