1 results (0.004 seconds)
CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0
CVE-2024-49219 – WordPress RS-Members plugin <= 1.0.3 - Privilege Escalation vulnerability
https://notcve.org/view.php?id=CVE-2024-49219
Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation.This issue affects RS-Members: from n/a through 1.0.3. The RS-Members plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.3. This is due to the plugin not properly restricting what roles a user can be assigned to. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their privileges to that of an administrator. • https://patchstack.com/database/vulnerability/rs-members/wordpress-rs-members-plugin-1-0-3-privilege-escalation-vulnerability?_s_id=cve • CWE-266: Incorrect Privilege Assignment •