Melapress Role Editor <= 1.1.1 - Improper Authorization to Authenticated (Subscriber+) Privilege Escalation via Secondary Role Assignment
2026-01-22 00:00
Sarawut Poolkhet (MisterHelloz)Strategic Overview
StatusPatched in 1.2.0
Affected PluginMelapress Role Editor
Affected Version
<= 1.1.1CVSS8.8High
CVE
CVE-2025-14866Vulnerability Overview
The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to assign themselves additional roles including Administrator.
Technical Analysis
REMEDIATION: Update to version 1.2.0, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C