PT-2026-35344 · Jgrodgers · Highland Software Custom Role Manager

Herc Bandiola

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7106

CVSS v3.1

8.8

High

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm save user roles() function, which is hooked to the personal options update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-7106

Affected Products

Highland Software Custom Role Manager