The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to assign themselves additional roles including Administrator.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Jan 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Melapress Role Editor plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.1. This is due to a misconfigured capability check on the 'save_secondary_roles_field' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to assign themselves additional roles including Administrator. | |
| Title | Melapress Role Editor <= 1.1.1 - Improper Authorization to Authenticated (Subscriber+) Privilege Escalation via Secondary Role Assignment | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-23T14:13:51.954Z
Reserved: 2025-12-18T01:55:21.873Z
Link: CVE-2025-14866
No data.
Status : Received
Published: 2026-01-23T13:15:47.983
Modified: 2026-01-23T13:15:47.983
Link: CVE-2025-14866
No data.
OpenCVE Enrichment
No data.