QID 150670

Date Published: 2023-04-17

QID 150670: WordPress User Role by BestWebSoft Plugin: Cross-Site Request Forgery (CSRF) vulnerability (CVE-2023-0820)

User Role is a WordPress plugin makes it easy to manage your WordPress website role capabilities.

The plugin lacks proper CSRF protection in requests that update role capabilities, allowing an attacker to escalate their privileges to any role on the site.

Affected versions:
User Role plugin prior to 1.6.7

QID Detection Logic :
This QID sends an HTTP GET request and retrieves a vulnerable version of a plugin running on the target application.

An authenticated attacker could potentially gain access to sensitive data or perform unauthorized actions on the site.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9.4 severity.
  • Solution
    Customers are advised to upgrade to User Role 1.6.7 or later version to remediate this vulnerability.

    CVEs related to QID 150670

    Software Advisories
    Advisory ID Software Component Link
    WPScan URL Logo wpscan.com/vulnerability/b93d9f9d-0fd9-49b8-b465-d32b95351912