The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: WPScan

Published: 2022-10-31T00:00:00

Updated: 2022-10-31T00:00:00

Reserved: 2022-10-07T00:00:00


Link: CVE-2022-3419

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-10-31T16:15:11.587

Modified: 2022-11-01T15:49:32.273


Link: CVE-2022-3419

JSON object: View

cve-icon Redhat Information

No data.