User Roles and Capabilities

User Roles and Capabilities has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for User Roles and Capabilities has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.

All of these findings were reported by domiee13. User Roles and Capabilities is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.7.17.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage0%
Open

1

Fixed

0

Get automatic notifications for all User Roles and Capabilities vulnerabilities before they are exploited.

Most severe open issueCVSS 4.3CVE-2025-49981

User Roles and Capabilities <= 1.2.6 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
User Roles and Capabilities banner
Latestv1.2.6

User Roles and Capabilities

mahabub81

Author

mahabub81

4.8(21)
96/100
Last Updated
2021-05-09 (5y ago)
Active Installs
7,000+
Downloads
128,056
Requires WP
3.5+
Requires PHP
0+
Tested up to
WP 5.7.17
Created
2015-02-03 (12y ago)

manage user roles and capabilities. Create new roles and delete existing roles. Using this plugin you will not be able to modify any capabilities for administrator user role. WordPress built in roles cant be deleted. If you find any issue just let us know we will get back to you with the fix in 24 hours. Features of Roles and Capabilities Fully tested by QA team. Create new roles. Delete existing roles. Clone existing roles. Rename Role Import / Export Roles and Capabilities Manage user Capabilities. set permission. Change default user role. Assign multiple roles to users. set permissions / capabilities to users. single screen to manage capability for all roles. easy to use.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C