The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2021-08-23T11:10:19

Updated: 2024-08-03T19:35:20.273Z

Reserved: 2021-01-14T00:00:00

Link: CVE-2021-24602

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-23T12:15:10.470

Modified: 2024-11-21T05:53:23.407

Link: CVE-2021-24602

cve-icon Redhat

No data.