Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-28183
PublishPress PublishPress Capabilities — WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U H H H 7.2 .0046 37.8 —
AFFECTED
Product Versions Fixed
PublishPress Capabilities unspecified 2.50.0
TIMELINE
Feb 25 Reserved by Patchstack
Aug 6 Published (CNA: Patchstack)
Sep 23 PATCH SHIPPED — CVE-2026-28183 (PublishPress Capabilities). Fixed in PublishPress Capabilities 2.50.0.
Description
Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| February 25, 2026 | Reserved | Reserved by Patchstack |
| August 6, 2026 | Published | Published (CNA: Patchstack) |
| September 23, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-28183 (PublishPress Capabilities). Fixed in PublishPress Capabilities 2.50.0. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| PublishPress | PublishPress Capabilities | — | — | 2.50.0 |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-28183 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.