Description
WordPress Plugin User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions by gaining administrator access. WordPress Plugin User Role Editor version 4.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.25 or latest
References
https://www.wordfence.com/blog/2016/04/user-role-editor-vulnerability/
Related Vulnerabilities
WordPress Plugin DVS Custom Notification Multiple Cross-Site Request Forgery Vulnerabilities (1.0.1)
WordPress Plugin Wow Moodboard Lite Open Redirect (1.1.1.1)
Joomla! Core 2.5.x Denial of Service (2.5.4 - 2.5.25)
Ruby on Rails URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2021-44528)