Adding drop down roles in registration <= 1.1 - Unauthenticated Privilege Escalation
criticalThe Adding drop down roles in registration plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1. This is due to the plugin not properly restricting what roles a user can register as. This makes it possible for unauthenticated attackers to register as an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.1
- Fix:
- No patched version reported
- Disclosed:
- Oct 14, 2024