User Role Editor

User Role Editor has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2024; all 2 are fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 2 high.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Improper Authorization.

Every one of the 2 issues recorded for User Role Editor has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by vgo0. User Role Editor is installed on roughly 700,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
8.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all User Role Editor vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8CVE-2024-12293

User Role Editor <= 4.64.3 - Cross-Site Request Forgery to Privilege Escalation

Read the full analysis

Vulnerability Records

2 records
User Role Editor banner
Latestv4.66.1

User Role Editor

Vladimir Garagulya

Author

Vladimir Garagulya

4.5(288)
90/100
Last Updated
2026-08-25 (19d ago)
Active Installs
700,000+
Downloads
22,573,555
Requires WP
4.6+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2010-03-22 (17y ago)

User Role Editor WordPress plugin allows you to change user roles and capabilities easy. Just turn on check boxes of capabilities you wish to add to the selected role and click “Update” button to save your changes. That’s done. Add new roles and customize its capabilities according to your needs, from scratch of as a copy of other existing role. Unnecessary self-made role can be deleted if there are no users whom such role is assigned. Role assigned every new created user by default may be changed too. Capabilities could be assigned on per user basis. Multiple roles could be assigned to user simultaneously. You can add new capabilities and remove unnecessary capabilities which could be left from uninstalled plugins. Multi-site support is provided. To read more about &#8216;User Role Editor’ visit this page Do you need more functionality with quality support in a real time? Do you wish to remove advertisements from User Role Editor pages? Buy Pro version. User Role Editor Pro includes extra modules: Block selected admin menu items for role. Hide selected front-end menu items for no logged-in visitors, logged-in users, roles. Block selected widgets under “Appearance” menu for role. Show widgets at front-end for selected roles. Block selected meta boxes (dashboard, posts, pages, custom post types) for role. “Export/Import” module. You can export user role to the local file and import it to any WordPress site or other sites of the multi-site WordPress network. Roles and Users permissions management via Network Admin for multisite configuration. One click Synchronization to the whole network. “Other roles access” module allows to define which other roles user with current role may see at WordPress: dropdown menus, e.g assign role to user editing user profile, etc. Manage user access to editing posts/pages/custom post type using posts/pages, authors, taxonomies ID list. Per plugin users access management for plugins activate/deactivate operations. Per form users access management for Gravity Forms plugin. Shortcode to show enclosed content to the users with selected roles only. Posts and pages view restrictions for selected roles. Admin back-end pages permissions viewer Pro version is advertisement free. Premium support is included. Additional Documentation You can find more information about “User Role Editor” plugin at this page I am ready to answer on your questions about plugin usage. Use plugin page comments for that.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C