Vulnerability in Multiple Roles per User Plugin for WordPress
CVE-2025-11620

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 November 2025

What is CVE-2025-11620?

The Multiple Roles per User plugin for WordPress has a security defect that allows authenticated users with the 'edit_users' capability to modify roles of other users without appropriate checks. Specifically, the functions 'mrpu_add_multiple_roles_ui' and 'mrpu_save_multiple_user_roles' lack proper capability validation, leading to a significant risk where attackers can promote themselves or others to Administrator, or demote existing Administrators to lower roles. This vulnerability impacts all versions up to and including 1.0, necessitating immediate update or remediation.

Affected Version(s)

Multiple Roles per User * <= 1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-11620 : Vulnerability in Multiple Roles per User Plugin for WordPress