CVE-2026-7106 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 27, 2026
Highland Software Custom Role Manager - Privilege Escalation
Overview
Highland Software Custom Role Manager plugin for WordPress <= 1.0.0 contains a privilege escalation caused by insufficient authorization checks in hscrm_save_user_roles() function, letting authenticated attackers with Subscriber-level access modify user roles via profile update form.
Severity & Score
Impact
Authenticated attackers can escalate privileges by modifying user roles, potentially gaining administrative access.
Mitigation
Update to a version later than 1.0.0 or the latest available version.
References
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/tags/1.0.0/includes/user-ui.php#L203
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/tags/1.0.0/includes/user-ui.php#L223
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/tags/1.0.0/includes/user-ui.php#L289
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/tags/1.0.1/includes/user-ui.php#L203
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/trunk/includes/user-ui.php#L203
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/trunk/includes/user-ui.php#L223
- https://plugins.trac.wordpress.org/browser/highland-software-custom-role-manager/trunk/includes/user-ui.php#L289
- https://www.wordfence.com/threat-intel/vulnerabilities/id/80a258a6-634c-4d7d-981f-bcbc0bb044f7?source=cve
Social Media Activity(2 posts)
š CVE-2026-7106 - High (8.8) The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked t... š https://www.thehackerwire.com/vulnerability/CVE-2026-7106/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postš CVE-2026-7106 - High (8.8) The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked t... š https://www.thehackerwire.com/vulnerability/CVE-2026-7106/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
View original postRelated Resources
Details
- CVE ID
- CVE-2026-7106
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- new
- EPSS
- 0.0%
- Social Posts
- 2
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H