VYPR

User Role

by WordPress

CVEs (3)

  • CVE-2023-0820HigApr 3, 2023
    risk 0.57cvss 8.8epss 0.00

    The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

  • CVE-2025-25114HigMar 3, 2025
    risk 0.46cvss 7.1epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ehabstar User Role user-roles allows Reflected XSS.This issue affects User Role: from n/a through <= 1.0.

  • CVE-2017-18566MedAug 20, 2019
    risk 0.40cvss 6.1epss 0.01

    The user-role plugin before 1.5.6 for WordPress has multiple XSS issues.