PT-2025-47251 · WordPress · Multiple Roles Per User

Published

2025-11-18

·

Updated

2025-11-23

·

CVE-2025-11620

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multiple Roles per User plugin for WordPress versions up to and including 1.0
Description The Multiple Roles per User plugin for WordPress has a flaw that allows unauthorized data modification. This is due to a missing capability check within the mrpu add multiple roles ui and mrpu save multiple user roles functions. Authenticated attackers with the 'edit users' capability can modify any user's role, potentially granting themselves administrator privileges or demoting existing administrators.
Recommendations Update the Multiple Roles per User plugin to a version beyond 1.0.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11620

Affected Products

Multiple Roles Per User