CVE-2022-3419: Automatic User Roles Switcher < 1.1.2 - Subscriber+ Privilege Escalation
Published Oct 31, 2022
·Updated
The Automatic User Roles Switcher WordPress plugin before 1.1.2 does not have authorisation and proper CSRF checks, allowing any authenticated users like subscriber to add any role to themselves, such as administrator
Affected Software
1 affected component
addify Automatic User Roles Switcher Wordpress<1.1.2
Event History
Oct 31, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Automatic User Roles Switcher WordPress plugin?
The vulnerability ID for the Automatic User Roles Switcher WordPress plugin is CVE-2022-3419.
2
What is the severity of CVE-2022-3419?
The severity of CVE-2022-3419 is medium (6.5).
3
What is the affected software for CVE-2022-3419?
The affected software for CVE-2022-3419 is the Automatic User Roles Switcher WordPress plugin before version 1.1.2.
4
What is the risk of CVE-2022-3419?
CVE-2022-3419 allows any authenticated users, such as subscribers, to add any role to themselves, including administrator.
5
How can I fix CVE-2022-3419?
To fix CVE-2022-3419, update the Automatic User Roles Switcher WordPress plugin to version 1.1.2 or newer.