VYPR
Medium severity4.3NVD Advisory· Published Jun 20, 2025· Updated Apr 23, 2026

CVE-2025-49981

CVE-2025-49981

Description

Missing authorization in User Roles and Capabilities plugin allows unprivileged users to exploit incorrectly configured access controls, potentially leading to privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in User Roles and Capabilities plugin allows unprivileged users to exploit incorrectly configured access controls, potentially leading to privilege escalation.

The User Roles and Capabilities WordPress plugin (versions up to 1.2.6) contains a missing authorization vulnerability. The plugin fails to properly verify user capabilities or nonce tokens in certain functions, resulting in broken access control. This flaw allows an attacker to bypass intended security restrictions.

An attacker who is already authenticated with minimal privileges (e.g., a subscriber or contributor) can exploit this vulnerability. No special network position is required; the attacker only needs to send crafted requests to the WordPress installation. The missing authorization check means the plugin does not enforce role-based restrictions for specific actions.

Successful exploitation enables the attacker to perform actions reserved for higher-privileged users, such as creating new administrator accounts, modifying user roles and capabilities, or altering plugin settings. This can lead to full site compromise if the attacker escalates privileges to administrator.

The vulnerability has been addressed in version 1.2.7 of the plugin. Users are strongly advised to update immediately. If updating is not possible, site administrators should review user accounts and consider restricting access to the plugin's functionality until a patch can be applied [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.