
CVE-2022-4974 – Freemius SDK <= 2.4.2 - Missing Authorization Checks
https://notcve.org/view.php?id=CVE-2022-4974
04 Mar 2022 — The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable. • https://www.wordfence.com/threat-intel/vulnerabilities/id/39fb0499-9ab4-4a2f-b0db-ece86bcf4d42?source=cve • CWE-862: Missing Authorization •

CVE-2021-24602 – HM Multiple Roles < 1.3 - Arbitrary Role Change
https://notcve.org/view.php?id=CVE-2021-24602
20 Jul 2021 — The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page El plugin de WordPress HM Múltiple Roles versiones anteriores a 1.3, no presenta ningún control de acceso para evitar a usuarios pocos privilegiados se establezcan como administradores por medio de su página de perfil. • https://jetpack.com/2021/08/05/privilege-escalation-in-hm-multiple-roles-wordpress-plugin • CWE-269: Improper Privilege Management CWE-669: Incorrect Resource Transfer Between Spheres •