The CVSS 7.5 rating for CVE-2026-12500 is almost certainly inflated, and here's why you should treat this as a medium-severity issue rather than high-severity in your prioritization.

The vulnerability is real: the plugin serves a nonce to unauthenticated visitors, then fails to verify capability before processing an AJAX handler that updates a WordPress option. That's a structural weakness—network-exploitable, no authentication required, integrity impact present. CVSS calculates 7.5 from that structure, and it's not wrong on those terms. But the calculation is incomplete in a way that matters enormously for actual risk.

WordPress stores virtually everything as an