Description
WordPress Plugin User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions by gaining administrator access. WordPress Plugin User Role Editor version 4.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.25 or latest
References
https://www.wordfence.com/blog/2016/04/user-role-editor-vulnerability/
Related Vulnerabilities
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2009-4030)
Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-41524)
WordPress Plugin Side Cart Woocommerce (Ajax) Cross-Site Request Forgery (2.0)
WordPress Plugin amtyThumb posts Cross-Site Scripting (8.1.3)