Vulnerability in Multiple Roles per User Plugin for WordPress
CVE-2025-11620
7.2HIGH
What is CVE-2025-11620?
The Multiple Roles per User plugin for WordPress has a security defect that allows authenticated users with the 'edit_users' capability to modify roles of other users without appropriate checks. Specifically, the functions 'mrpu_add_multiple_roles_ui' and 'mrpu_save_multiple_user_roles' lack proper capability validation, leading to a significant risk where attackers can promote themselves or others to Administrator, or demote existing Administrators to lower roles. This vulnerability impacts all versions up to and including 1.0, necessitating immediate update or remediation.
Affected Version(s)
Multiple Roles per User * <= 1.0