The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2023-04-03T14:38:25.817Z
Updated: 2024-08-02T05:24:34.435Z
Reserved: 2023-02-13T21:06:49.336Z
Link: CVE-2023-0820
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-03T15:15:18.920
Modified: 2024-11-21T07:37:54.033
Link: CVE-2023-0820
Redhat
No data.