LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-7106 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 27, 2026

Highland Software Custom Role Manager - Privilege Escalation

Published: April 27, 2026Updated: April 27, 2026Remote Exploitable

Overview

Highland Software Custom Role Manager plugin for WordPress <= 1.0.0 contains a privilege escalation caused by insufficient authorization checks in hscrm_save_user_roles() function, letting authenticated attackers with Subscriber-level access modify user roles via profile update form.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated attackers can escalate privileges by modifying user roles, potentially gaining administrative access.

Mitigation

Update to a version later than 1.0.0 or the latest available version.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 27, 2026

🟠 CVE-2026-7106 - High (8.8) The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked t... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-7106/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 27, 2026

🟠 CVE-2026-7106 - High (8.8) The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked t... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-7106/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-7106
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-269

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days