The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
History

Tue, 06 May 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2022-10-31T00:00:00.000Z

Updated: 2025-05-06T20:12:09.630Z

Reserved: 2022-10-07T00:00:00.000Z

Link: CVE-2022-3419

cve-icon Vulnrichment

Updated: 2024-08-03T01:07:06.705Z

cve-icon NVD

Status : Modified

Published: 2022-10-31T16:15:11.587

Modified: 2025-05-06T21:15:54.033

Link: CVE-2022-3419

cve-icon Redhat

No data.