Multiple E-plugins (Various Versions) - Authenticated (Subscriber+) Privilege Escalation
highMultiple plugins by the vendor E-plugins are vulnerable to privilege escalation due to insufficient restriction on several functions called via AJAX actions that set a user's role based on supplied role information. This makes it possible authenticated, subscriber-level and above attackers to elevate their privileges t...
- CVSS:
- 8.8
- Affected:
- up to *
- Fix:
- No patched version reported
- Disclosed:
- Mar 6, 2023