Multiple E-plugins (Various Versions) - Authenticated (Subscriber+) Privilege Escalation
highMultiple plugins by the vendor E-plugins are vulnerable to privilege escalation due to insufficient restriction on several functions called via AJAX actions that set a user's role based on supplied role information. This makes it possible authenticated, subscriber-level and above attackers to elevate their privileges t...
- CVSS:
- 8.8
- Affected:
- up to 1.0.9
- Fixed in:
- 1.0.9
- Disclosed:
- Mar 6, 2023