PT-2025-47251 · WordPress · Multiple Roles Per User
Published
2025-11-18
·
Updated
2025-11-23
·
CVE-2025-11620
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Multiple Roles per User plugin for WordPress versions up to and including 1.0
Description
The Multiple Roles per User plugin for WordPress has a flaw that allows unauthorized data modification. This is due to a missing capability check within the
mrpu add multiple roles ui and mrpu save multiple user roles functions. Authenticated attackers with the 'edit users' capability can modify any user's role, potentially granting themselves administrator privileges or demoting existing administrators.Recommendations
Update the Multiple Roles per User plugin to a version beyond 1.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Multiple Roles Per User