plugin

Multiple Roles Vulnerabilities

2 known security issues reported for the Multiple Roles WordPress plugin. Most recent disclosed Jul 26, 2022.

1 high 1 medium

Running Multiple Roles on your site? Check whether your installed version is affected.

Scan your site free

Multiple Roles < 1.3.7 - Privilege Escalation

high

The Multiple Roles plugin for WordPress is vulnerable to privilege escalation in versions before 1.3.7. This could allow authenticated attackers to escalate their privileges by updating user roles on the site.

CVSS:
8.8
Affected:
up to 1.3.7
Fixed in:
1.3.7
Disclosed:
Jul 26, 2022

Multiple Roles <= 1.3.1- Cross-Site Request Forgery Bypass

medium

The Multiple Roles plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.3.1. This is due to missing or incorrect nonce validation on the mu_add_roles_in_signup_meta() and mu_add_roles_in_signup_meta_recently() functions. This makes it possible for unauthenticated attacker...

CVSS:
4.3
Affected:
up to 1.3.1
Fixed in:
1.3.2
Disclosed:
Jun 8, 2021

CVE-2021-4402 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database