User Roles and Capabilities
User Roles and Capabilities has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for User Roles and Capabilities has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by domiee13. User Roles and Capabilities is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.7.17.
CVE-2025-49981User Roles and Capabilities <= 1.2.6 - Missing Authorization
Read the full analysisVulnerability Records

User Roles and Capabilities
Author
mahabub81
manage user roles and capabilities. Create new roles and delete existing roles. Using this plugin you will not be able to modify any capabilities for administrator user role. WordPress built in roles cant be deleted. If you find any issue just let us know we will get back to you with the fix in 24 hours. Features of Roles and Capabilities Fully tested by QA team. Create new roles. Delete existing roles. Clone existing roles. Rename Role Import / Export Roles and Capabilities Manage user Capabilities. set permission. Change default user role. Assign multiple roles to users. set permissions / capabilities to users. single screen to manage capability for all roles. easy to use.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C