CVE 8.8 HIGH

Highland Software Custom Role Manager <= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation_CVE-2026-7106

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

AI Analysis

Privilege Escalation vulnerability due to insufficient authorization checks in the hscrm_save_user_roles() function

Basic Information

ID CVE-2026-7106
Source Wordfence
Published Apr 27, 2026 at 02:26

Affected Product

Vendor jgrodgers
Product Highland Software Custom Role Manager
Affected Versions jgrodgers Highland Software Custom Role Manager 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor jgrodgers
Product Highland Software Custom Role Manager
Version 1.0.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.