Security Advisory
CVE-2026-77003
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The Content Mask WordPress plugin before 1.8.5.5 does not check the capability required to publish the post type being created, allowing users with a role as low as Contributor to publish posts and pages on the site without holding the publish capability.