User Role Editor

The User Role Editor WordPress plugin allows users to easily change user roles and capabilities, add new roles, and customize capabilities. Users can also delete unnecessary self-made roles and change the default role assigned to new users. Capabilities can be assigned on a per-user basis, and multiple roles can be assigned to a user simultaneously. The plugin also supports multi-site functionality. The Pro version includes additional modules such as blocking selected admin menu items, hiding front-end menu items, and blocking selected widgets.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in User Role Editor 4.64.3

    Fixed

    The User Role Editor plugin for WordPress has a security issue that affects all versions up to 4.64.3. This is because the plugin does not properly check for a certain security code when updating use...

    Read More
  • Access violation vulnerability in User Role Editor 4.25

    Fixed

    The User Role Editor plugin for WordPress has a security flaw that could allow anyone who is logged in to the system to give themselves the administrator role. This vulnerability is present in versio...

    Read More