
CVE-2026-0912 pertains to a security flaw within the Toret Manager plugin for WordPress, specifically affecting all versions up to and including 1.2.7. The core issue is a missing capability check in the functions `trman_save_option` and `trman_save_option_items`. This omission allows authenticated users with Subscriber-level access or higher to modify arbitrary options within the plugin, which can lead to privilege escalation. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #PrivilegeEscalation #Apple https://cvetodo.com/cve/CVE-2026-0912
Post summary
CVE‑2026‑0912 is a privilege escalation flaw in the Toret Manager WordPress plugin caused by missing capability checks, affecting all versions up to 1.2.7 and allowing authenticated users to modify arbitrary plugin options.
