ZeroHour

CVE-2022-3419

PoC
CVSS 3.1
6.5 medium
EPSS
<1%p28
Published
()
Modified
Description

The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator

Vendors
addify
Products
automatic user roles switcher
Ecosystems
WordPress
Weakness
CWE-269, CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.