{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/propovoice-all-in-one-client-management-system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15312"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Propovoice: All-in-One Client Management System"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe Propovoice: All-in-One Client Management System plugin for WordPress contains a critical privilege escalation vulnerability (CVE-2026-15312) in all versions up to and including 1.7.8. The vulnerability originates in the plugin's REST API, specifically within the \u003ccode\u003ecreate()\u003c/code\u003e function. This function fails to implement necessary authorization checks to verify if the requesting user possesses the \u003ccode\u003epromote_users\u003c/code\u003e capability before modifying user roles. Furthermore, the endpoint fails to validate user-supplied \u003ccode\u003erole\u003c/code\u003e parameters against an allowlist, allowing an attacker to pass arbitrary role names directly to the \u003ccode\u003eWP_User::set_role()\u003c/code\u003e WordPress function.\u003c/p\u003e\n\u003cp\u003eThis flaw is particularly significant because it allows any user already holding the \u003ccode\u003endpv_manager\u003c/code\u003e role - a role granted by the Propovoice plugin itself - to elevate their account or create new accounts with full administrative privileges. This provides attackers with a path to full site compromise once they have obtained lower-level management access, making the plugin a high-value target for privilege escalation within WordPress environments.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid credentials for a user account with the \u003ccode\u003endpv_manager\u003c/code\u003e capability assigned by the Propovoice plugin.\u003c/li\u003e\n\u003cli\u003eAttacker logs into the WordPress environment using these credentials to initiate authenticated sessions.\u003c/li\u003e\n\u003cli\u003eAttacker identifies the vulnerable REST API endpoint exposed by the Propovoice plugin associated with the \u003ccode\u003ecreate()\u003c/code\u003e function.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious HTTP POST request targeting the endpoint, embedding the \u003ccode\u003erole\u003c/code\u003e parameter set to \u003ccode\u003eadministrator\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe server-side REST API fails to perform a capability check for \u003ccode\u003epromote_users\u003c/code\u003e and neglects to validate the \u003ccode\u003erole\u003c/code\u003e input against an allowlist.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eWP_User::set_role()\u003c/code\u003e function is invoked by the plugin with the attacker-supplied \u003ccode\u003eadministrator\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThe user account is promoted, or a new user is created, with full administrative access to the WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker uses administrative access to perform further malicious actions, such as plugin/theme modification or arbitrary code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative control over the affected WordPress instance. Attackers can leverage this access to modify site content, install malicious plugins, gain persistence, and exfiltrate sensitive data managed within the CRM system. This vulnerability impacts any WordPress site utilizing Propovoice versions 1.7.8 or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Propovoice plugin to the latest patched version available from the vendor.\u003c/li\u003e\n\u003cli\u003eAudit existing WordPress user accounts for unexpected administrative role assignments occurring within the same timeframe as access logs showing suspicious REST API activity.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests to the REST API endpoints associated with user management in the Propovoice plugin.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-15T04:16:54Z","date_published":"2026-08-15T04:16:54Z","id":"https://feed.craftedsignal.io/briefs/2026-08-propovoice-privilege-escalation/","summary":"An improper capability check in the Propovoice plugin for WordPress (\u003c= 1.7.8) allows authenticated users with the 'ndpv_manager' role to escalate their privileges to administrator by exploiting the REST API's user creation function.","title":"Propovoice Plugin Privilege Escalation Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-08-propovoice-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - Propovoice: All-in-One Client Management System","version":"https://jsonfeed.org/version/1.1"}