CVE-2023-0820: User Role by BestWebSoft < 1.6.7 - Privilege Escalation via CSRF
Published Apr 3, 2023
·Updated
The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
Affected Software
1 affected component
Bestwebsoft User Role Wordpress<1.6.7
Event History
Apr 3, 2023
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the User Role by BestWebSoft WordPress plugin?
The vulnerability ID for the User Role by BestWebSoft WordPress plugin is CVE-2023-0820.
2
What is the severity of CVE-2023-0820?
CVE-2023-0820 has a severity score of 8.8, which is considered high.
3
What does CVE-2023-0820 affect?
CVE-2023-0820 affects the User Role by BestWebSoft WordPress plugin versions up to but excluding 1.6.7.
4
What is the risk associated with CVE-2023-0820?
CVE-2023-0820 allows for arbitrary privilege escalation of any role in the User Role by BestWebSoft WordPress plugin.
5
Is there a fix available for CVE-2023-0820?
Yes, updating the User Role by BestWebSoft WordPress plugin to version 1.6.7 or later will fix the vulnerability.