User Role
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0820 | Hig | 0.57 | 8.8 | 0.00 | Apr 3, 2023 | The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role. | ||
| CVE-2025-25114 | Hig | 0.46 | 7.1 | 0.00 | Mar 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role user-roles allows Reflected XSS.This issue affects User Role: from n/a through <= 1.0. | ||
| CVE-2017-18566 | Med | 0.40 | 6.1 | 0.01 | Aug 20, 2019 | The user-role plugin before 1.5.6 for WordPress has multiple XSS issues. |
- risk 0.57cvss 8.8epss 0.00
The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
- risk 0.46cvss 7.1epss 0.00
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role user-roles allows Reflected XSS.This issue affects User Role: from n/a through <= 1.0.
- risk 0.40cvss 6.1epss 0.01
The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.