#CWE-269
All CosmicBytez Labs articles tagged #CWE-269, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-77203: WordPress Groups Plugin Privilege Escalation
A flaw in groups_join() lets Subscriber-level WordPress users self-enroll into admin groups, escalating to full Administrator privileges.
- Security
CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege
TheCartPress WordPress plugin 1.5.3.6 allows unauthenticated attackers to register new administrator accounts by exploiting the AJAX handler with a...
- Security
CVE-2026-32922: OpenClaw Privilege Escalation via Token
A critical CVSS 9.9 privilege escalation vulnerability in OpenClaw allows operators with limited pairing scope to mint tokens with unrestricted admin...
- Security
CVE-2026-3629: WordPress User Import Plugin Privilege
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to 1.29.7, allowing authenticated...
- Security
CVE-2026-25770: Wazuh Privilege Escalation to Root via Cluster Protocol File Write
A critical privilege escalation vulnerability (CVSS 9.1) in Wazuh versions 3.9.0–4.14.2 allows authenticated cluster nodes to overwrite the manager...