Description
WordPress Plugin User Role Editor is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions by gaining administrator access. WordPress Plugin User Role Editor version 4.24 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 4.25 or latest
References
https://www.wordfence.com/blog/2016/04/user-role-editor-vulnerability/
Related Vulnerabilities
WordPress Plugin Booster for WooCommerce PHP Object Injection (3.0.1)
WordPress Plugin Exit Popup Show Cross-Site Scripting (1.0)
WordPress Plugin WP SEO Redirect 301 Cross-Site Request Forgery (2.3.1)
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2015-2935)
WordPress Plugin WP Simple Booking Calendar SQL Injection (2.0.6)