ZeroHour

CVE-2023-0820

PoC
CVSS 3.1
8.8 high
EPSS
<1%p35
Published
()
Modified
Description

The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

Vendors
bestwebsoft
Products
user role
Ecosystems
WordPress
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.