Description
WordPress Plugin HM Multiple Roles is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change their role to admin. WordPress Plugin HM Multiple Roles version 1.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.3 or latest
References
https://wordpress.org/support/topic/security-issue-117/
https://sploitus.com/exploit?id=WPEX-ID:5FD2548A-08DE-4417-BFF1-F174DAB718D5
https://plugins.svn.wordpress.org/hm-multiple-roles/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin LIQUID SPEECH BALLOON Cross-Site Scripting (1.0.6)
WordPress Plugin WooCommerce PayPlug Unspecified Vulnerability (3.1.0)
WordPress Plugin NextGEN Gallery-WordPress Gallery 'swfupload.swf' Cross-Site Scripting (1.9.7)
WordPress Plugin Migration, Backup, Staging-WPvivid Cross-Site Scripting (0.9.55)