The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-352 | |
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-02-14T16:53:04.935Z
Reserved: 2023-02-13T21:06:49.336Z
Link: CVE-2023-0820

Updated: 2024-08-02T05:24:34.435Z

Status : Modified
Published: 2023-04-03T15:15:18.920
Modified: 2025-02-14T17:15:13.047
Link: CVE-2023-0820

No data.