Vulnerability in Multiple Roles per User Plugin for WordPress
CVE-2025-11620
What is CVE-2025-11620?
The Multiple Roles per User plugin for WordPress has a security defect that allows authenticated users with the 'edit_users' capability to modify roles of other users without appropriate checks. Specifically, the functions 'mrpu_add_multiple_roles_ui' and 'mrpu_save_multiple_user_roles' lack proper capability validation, leading to a significant risk where attackers can promote themselves or others to Administrator, or demote existing Administrators to lower roles. This vulnerability impacts all versions up to and including 1.0, necessitating immediate update or remediation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Multiple Roles per User * <= 1.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved