PT-2025-44944 · Tanvirahmed1984+1 · Simple User Capabilities
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Simple User Capabilities versions prior to 1.1
Description
The plugin allows unauthenticated attackers to reset the capabilities of any user. This occurs because the 'wp ajax nopriv reset capability' AJAX endpoint lacks a proper capability check, leading to unauthorized modification of data.
Recommendations
Update the plugin to a version later than 1.0.
As a temporary mitigation, restrict access to the 'wp ajax nopriv reset capability' AJAX endpoint.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simple User Capabilities