The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-10-31T00:00:00
Updated: 2024-08-03T01:07:06.705Z
Reserved: 2022-10-07T00:00:00
Link: CVE-2022-3419
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-10-31T16:15:11.587
Modified: 2024-11-21T07:19:28.593
Link: CVE-2022-3419
Redhat
No data.