CVE-2026-4297PoC

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions up to and including 0.0.31. This is due to a missing capability check in the nc_setOption() function, which is exposed via the nc.setOption XML-RPC method. The function authenticates the user via $wp_xmlrpc_server->login() (verifying credentials are valid) but does not perform any authorization check such as current_user_can('manage_options'). This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary WordPress options via XML-RPC requests. This can be leveraged to change the default_role option to 'administrator' and then register a new administrator account, achieving full privilege escalation and site takeover.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-24); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-24: 1Mentions · 2026-08-03: 1PoC Mentioned / Linked · 2026-06-24: 1Technical Details · 2026-06-24: 1Technical Details · 2026-08-03: 106-2408-03
Signal classification2 categories
PoC
150.0%
General
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-06-241
PoC1
2026-08-031
General1
Full discourse2 posts
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    General

    CVSS 8.8. CVE-2026-4297. Worth reading before your users find out the hard way. The Welcome Software Publishing plugin for WordPress is vulnerable to Arbitrary Options Update in all versions u... The best defense is the one you set up before you needed it.

    Post summary

    The post announces CVE-2026-4297 for the Welcome Software Publishing WordPress plugin, noting a high CVSS score and an arbitrary options update flaw, but provides no PoC, exploit, or patch information.

    0002158
    346 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4297-newscred-publishing-version-0-0-31-high-vulnerability-proof-of-concept CVE-2026-4297 newscred-publishing (CVSS Score 8.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #a

    Post summary

    A proof‑of‑concept for CVE‑2026‑4297, affecting the Newscred‑Publishing WordPress plugin, has been posted, highlighting a high‑severity vulnerability (CVSS 8.8) but no active exploitation, exploit code, or patch information is provided.

    0000026
    11 followersView on X

Explore more