WordPress security by component
Bulk Change Role
Plugin description
Bulk Change Role is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Oct 30, 2024; the highest published CVSS base score is 8.8.
Plugin slug:
bulk-role-changeLatest vulnerability
CVE-2024-50504: Bulk Change Role: Privilege escalation or authentication bypass
Bulk Change Role is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
| Safe version |
|
||
|---|---|---|---|
| Oct 30, 2024 |
CVE-2024-50504
Bulk Change Role: Privilege escalation or authentication bypass
Bulk Change Role is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE8.8
NVDPending
|