Impact
The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data because all versions up to 1.0 lack a capability check on the functions that add and save user roles. An authenticated user who has the 'edit_users' capability can change any other user's role, promoting them to Administrator or demoting existing Administrators to lower‑privileged roles.
Affected Systems
The affected system is the WordPress Multiple Roles per User plugin, developed by jemoreto. All released versions up to and including 1.0 are affected.
Risk and Exploitability
The CVSS score of 7.2 indicates a medium‑to‑high severity vulnerability that can be exploited by any authenticated user with edit_users rights. The EPSS score is below 1%, suggesting a very low probability of exploitation at present, though the issue is not listed in CISA's KEV catalog. A likely attack vector is a local authenticated attacker using a WordPress user account with edit_users capability to modify role assignments.
OpenCVE Enrichment