Multiple Roles < 1.3.7 - Privilege Escalation
high
The Multiple Roles plugin for WordPress is vulnerable to privilege escalation in versions before 1.3.7. This could allow authenticated attackers to escalate their privileges by updating user roles on the site.
- CVSS:
- 8.8
- Affected:
- up to 1.3.7
- Fixed in:
- 1.3.7
- Disclosed:
- Jul 26, 2022
Multiple Roles <= 1.3.1- Cross-Site Request Forgery Bypass
medium
The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the mu_add_roles_in_signup_meta() and mu_add_roles_in_signup_meta_recently() functions. This makes it possible for unauthenticated attacker...
- CVSS:
- 4.3
- Affected:
- up to 1.3.1
- Fixed in:
- 1.3.2
- Disclosed:
- Jun 8, 2021
CVE-2021-4402 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database