HM Multiple Roles <= 1.2 - Privilege Escalation via Arbitrary Role Change

2021-07-20 00:00
clemorphy

Strategic Overview

Status
Patched in 1.3
Affected PluginHM Multiple Roles
Affected Version<= 1.2
CVSS8.8High
CVECVE-2021-24602
View all HM Multiple Roles vulnerabilities

Vulnerability Overview

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

Technical Analysis

REMEDIATION: Update to version 1.3, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C