CVE-2023-0820

T

he User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.

Configurations

Configuration 1 (hide)

cpe:2.3:a:bestwebsoft:user_role:*:*:*:*:*:wordpress:*:*

History

14 Feb 2025, 17:15

Type Values Removed Values Added
CWE CWE-352

21 Nov 2024, 07:37

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/b93d9f9d-0fd9-49b8-b465-d32b95351912 - Exploit, Third Party Advisory () https://wpscan.com/vulnerability/b93d9f9d-0fd9-49b8-b465-d32b95351912 - Exploit, Third Party Advisory

Information

Published : 2023-04-03 15:15

Updated : 2025-02-14 17:15


NVD link : CVE-2023-0820

Mitre link : CVE-2023-0820

CVE.ORG link : CVE-2023-0820


JSON object : View

Products Affected
CWE
CWE-352

Cross-Site Request Forgery (CSRF)