Highland Software Custom Role Manager
Highland Software Custom Role Manager has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of August 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Improper Privilege Management, behind 1 of the records (100%).
The one issue recorded for Highland Software Custom Role Manager has a vendor fix available, so running the current release closes it.
All of these findings were reported by 0xHerc. The current release is tested up to WordPress 7.0.4.
CVE-2026-7106Highland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation
Read the full analysisVulnerability Records

Highland Software Custom Role Manager
Author
jgrodgers
Highland Software Custom Roles Manager extends WordPress role management by allowing administrators to create custom roles, assign multiple roles to users, and manage capabilities through an intuitive interface. This plugin follows WordPress best practices for role and capability management, including strict server-side validation and protection against unsafe capability assignment. Version 1.0.3 improves role loading, synchronization, and compatibility with third-party plugins by automatically detecting and rendering dynamically registered WordPress roles. The plugin now correctly displays existing user roles and automatically detects roles created by third-party plugins such as WooCommerce, LMS platforms, membership systems, CRM integrations, and other custom role providers — without requiring administrators to resave settings. Features Create and manage unlimited custom roles Assign multiple roles to a single user Automatic detection of third-party and plugin-created roles Existing user roles automatically displayed and synchronized Group roles for better organization Drag-and-drop role ordering Capability management with toggle interface Role and capability change logging (audit trail) Protection against unsafe capability assignment Replace the default role dropdown with a checkbox-based interface Support for WordPress core roles and custom plugin roles Automatic synchronization with newly registered WordPress roles
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C