PT-2026-35344 · Jgrodgers · Highland Software Custom Role Manager
Herc Bandiola
·
Published
2026-04-27
·
Updated
2026-04-27
·
CVE-2026-7106
CVSS v3.1
8.8
High
| AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm save user roles() function, which is hooked to the personal options update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Highland Software Custom Role Manager