← Back to CVE List
CVE-2023-0820
The User Role by BestWebSoft WordPress plugin before 1.6.7 does not protect against CSRF in requests to update role capabilities, leading to arbitrary privilege escalation of any role.
> MITRE Terms of Use apply – see LICENSE‑MITRE.txt