PT-2022-22058 · WordPress · Automatic User Roles Switcher

Published

2022-10-31

·

Updated

2022-11-01

·

CVE-2022-3419

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Automatic User Roles Switcher WordPress plugin versions prior to 1.1.2
Description The issue concerns a lack of proper authorization and CSRF checks, allowing authenticated users, such as subscribers, to add any role to themselves, including administrator.
Recommendations For versions prior to 1.1.2, update to version 1.1.2 or later to resolve the issue. As a temporary workaround, consider restricting access to role management features to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-3419

Affected Products

Automatic User Roles Switcher