WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
highThe WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the att...
- CVSS:
- 8.8
- Affected:
- up to 3.7.1
- Fixed in:
- 3.7.2
- Disclosed:
- Jul 27, 2026