ZeroHour

CVE-2021-24602

PoC
CVSS 3.1
8.8 high
EPSS
2%p73
Published
()
Modified
Description

The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page

Vendors
hmplugin
Products
hm multiple roles
Ecosystems
WordPress
Weakness
CWE-269, CWE-669
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.