PT-2026-35344 · WordPress · Custom Role Manager

Herc Bandiola

·

Published

2026-04-27

·

Updated

2026-06-04

·

CVE-2026-7106

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Highland Software Custom Role Manager versions prior to 1.0.1
Description The Highland Software Custom Role Manager plugin for WordPress allows privilege escalation due to insufficient authorization checks in the hscrm save user roles() function. This function is hooked to the personal options update action, which is accessible to any authenticated user. Consequently, attackers with Subscriber-level access or higher can potentially modify user roles through the profile update form.
Recommendations Update to a version later than 1.0.0. As a temporary workaround, restrict access to the hscrm save user roles() function to prevent unauthorized role modifications.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7106

Affected Products

Custom Role Manager