Highland Software Custom Role Manager

Highland Software Custom Role Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Improper Privilege Management, behind 1 of the records (100%).

The one issue recorded for Highland Software Custom Role Manager has a vendor fix available, so running the current release closes it.

All of these findings were reported by 0xHerc. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Highland Software Custom Role Manager vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2026-7106

Highland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation

Read the full analysis

Vulnerability Records

1 records
Highland Software Custom Role Manager banner
Latestv1.0.5

Highland Software Custom Role Manager

jgrodgers

Author

jgrodgers

0.0(0)
0/100
Last Updated
2026-08-06 (9d ago)
Active Installs
0+
Downloads
727
Requires WP
5.4+
Requires PHP
7.2+
Tested up to
WP 7.0.4
Created
2026-04-25 (4mo ago)

Highland Software Custom Roles Manager extends WordPress role management by allowing administrators to create custom roles, assign multiple roles to users, and manage capabilities through an intuitive interface. This plugin follows WordPress best practices for role and capability management, including strict server-side validation and protection against unsafe capability assignment. Version 1.0.3 improves role loading, synchronization, and compatibility with third-party plugins by automatically detecting and rendering dynamically registered WordPress roles. The plugin now correctly displays existing user roles and automatically detects roles created by third-party plugins such as WooCommerce, LMS platforms, membership systems, CRM integrations, and other custom role providers — without requiring administrators to resave settings. Features Create and manage unlimited custom roles Assign multiple roles to a single user Automatic detection of third-party and plugin-created roles Existing user roles automatically displayed and synchronized Group roles for better organization Drag-and-drop role ordering Capability management with toggle interface Role and capability change logging (audit trail) Protection against unsafe capability assignment Replace the default role dropdown with a checkbox-based interface Support for WordPress core roles and custom plugin roles Automatic synchronization with newly registered WordPress roles

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C