Description
WordPress Plugin HM Multiple Roles is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently change their role to admin. WordPress Plugin HM Multiple Roles version 1.2 is vulnerable; prior versions are also affected.
Remediation
Update to plugin version 1.3 or latest
References
https://wordpress.org/support/topic/security-issue-117/
https://sploitus.com/exploit?id=WPEX-ID:5FD2548A-08DE-4417-BFF1-F174DAB718D5
https://plugins.svn.wordpress.org/hm-multiple-roles/trunk/readme.txt