CVE-2021-24602

Severity CVSS v4.0:
Pending analysis
Type:
CWE-669 Incorrect Resource Transfer Between Spheres
Publication date:
23/08/2021
Last modified:
25/10/2022

Description

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hmplugin:hm_multiple_roles:*:*:*:*:*:wordpress:*:* 1.3 (excluding)