The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2024-08-03T01:07:06.705Z
Reserved: 2022-10-07T00:00:00
Link: CVE-2022-3419

No data.

Status : Modified
Published: 2022-10-31T16:15:11.587
Modified: 2024-11-21T07:19:28.593
Link: CVE-2022-3419

No data.