← WordPress Vulnerabilities
WordPress security by component

Bulk Change Role

Bulk Change Role is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 30, 2024; the highest published CVSS base score is 8.8.

Plugin slug: bulk-role-change

CVE-2024-50504: Bulk Change Role: Privilege escalation or authentication bypass

Bulk Change Role is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedOct 30, 2024
Safe version guidanceSee mitigation notes
Published vulnerabilities for bulk-role-change
Safe version
Oct 30, 2024 CVE-2024-50504
Bulk Change Role: Privilege escalation or authentication bypass
Bulk Change Role is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE8.8
NVDPending