The HM Multiple Roles plugin for WordPress did not have a security feature to stop people with low levels of access from changing their own profile to make themselves an administrator. This was fixed in version 1.3.
Documentation: Home / Vulnerabilities / Access violation vulnerability in HM Multiple Roles 1.2
The HM Multiple Roles plugin for WordPress did not have a security feature to stop people with low levels of access from changing their own profile to make themselves an administrator. This was fixed in version 1.3.
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.
© Really Simple Plugins
CoC 70461155
Kalmarweg 14-5
9723 JG, Groningen (NL)