{"error":0,"message":null,"data":{"name":"User Role Editor","plugin":"user-role-editor","link":"https:\/\/wordpress.org\/plugins\/user-role-editor\/","latest":"1787649540","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"039de54a6b877353e48a496de37535c08ec92167a4aeb7730fec92a8b82bac8f","name":"User Role Editor [user-role-editor] < 4.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"f814ebd7f3c5283e94417912def596f19b5b9156","name":"WordPress User Role Editor Plugin <= 4.24 - Privilege Escalation","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-role-editor\/vulnerability\/wordpress-user-role-editor-plugin-4-24-privilege-escalation","description":"Because of this vulnerability, any registered user can gain administrator access.\nUpgrade the plugin.","date":"2016-04-05"}],"impact":[]},{"uuid":"ac9d8da8860051063a912fec264179b11442592e510b56169cd5d1cfb79fe3e8","name":"User Role Editor [user-role-editor] < 3.13","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.13","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"366159f2b60b80c1e8e2ccb1f7332c1c6b57f3a9","name":"WordPress User Role Editor Plugin 3.12 - CSRF","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-role-editor\/vulnerability\/wordpress-user-role-editor-plugin-3-12-csrf","description":"User Role Editor plugin is prone to a cross site request forgery vulnerability.  It allows an attacker to gain unauthorized access to the affected application by performing certain actions in the context of an authorized user's session.\nUpdate the plugin.","date":"2013-05-26"}],"impact":[]},{"uuid":"1e30aed1c08ddc0745d855d37d33aba3a33b0bc1581cfede0da8dd85b2509d49","name":"User Role Editor [user-role-editor] < 4.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"85e595f5-9f04-4799-9a09-c6675071b12c","name":"wpscan.com","link":"https:\/\/wpscan.com\/vulnerability\/85e595f5-9f04-4799-9a09-c6675071b12c","description":null,"date":null}],"impact":[]},{"uuid":"2b4078801e7bde0267d26117934e3f4162675da47ff52e83f9285cea648f58fc","name":"User Role Editor [user-role-editor] < 3.14","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.14","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b938aa1e-eb2b-4f9b-87a6-ad91e6c1223d","name":"User Role Editor - Cross-Site Request Forgery","link":"https:\/\/wpscan.com\/vulnerability\/b938aa1e-eb2b-4f9b-87a6-ad91e6c1223d","description":"The User Role Editor WordPress plugin was affected by a Cross-Site Request Forgery  security vulnerability.","date":null}],"impact":[]},{"uuid":"74da2607d5c357925d1efa9694c368580084f86c9ad49410853729d46f527ef4","name":"User Role Editor [user-role-editor] < 4.25","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.25","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"70c2180d5ba6cee2e9b1836583915ab6520c49cd","name":"User Role Editor <= 4.24 - Authenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-role-editor\/user-role-editor-424-authenticated-privilege-escalation","description":"The User Role Editor plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'update' function in versions up to, and including, 4.24. This makes it possible for any authenticated attackers to grant themselves the administrator role.","date":"2016-04-04"}],"impact":[]},{"uuid":"ac68e8ecff34ae448a15963362bb7e4473a3f80b976b0b491ad6ccab4035469d","name":"User Role Editor [user-role-editor] < 4.64.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.64.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-12293","name":"CVE-2024-12293","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-12293","description":"[en] The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or remove roles for arbitrary users, including escalating their privileges to administrator, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-12-17"},{"id":"6f7e73727a228d768c548a9b305a67086a486591","name":"User Role Editor <= 4.64.3 - Cross-Site Request Forgery to Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-role-editor\/user-role-editor-4643-cross-site-request-forgery-to-privilege-escalation","description":"The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or remove roles for arbitrary users, including escalating their privileges to administrator, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-12-16"},{"id":"4aeaae52f4573ebc3f73b1d6941463963632d3e6","name":"WordPress User Role Editor Plugin <= 4.64.3 is vulnerable to Cross Site Request Forgery (CSRF)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-role-editor\/vulnerability\/wordpress-user-role-editor-plugin-4-64-3-cross-site-request-forgery-to-privilege-escalation-vulnerability","description":"<p>WordPress User Role Editor Plugin <= 4.64.3 is vulnerable to Cross Site Request Forgery (CSRF)<\/p><p>Software: User Role Editor<\/p><p>Fixed in version 4.64.4 <\/p><p>Affected Version <= 4.64.3<\/p><p>CVE: CVE-2024-12293<\/p>","date":"2024-12-16"},{"id":"EUVD-2024-50749","name":"EUVD-2024-50749","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2024-50749","description":"The User Role Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.64.3. This is due to missing or incorrect nonce validation on the update_roles() function. This makes it possible for unauthenticated attackers to add or remove roles for arbitrary users, including escalating their privileges to administrator, via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2024-12-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.001"}}]},"updated":"1785853657"}