cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forhm-multiple-roles hm-multiple-roles

Direction: ascending
Jun 07, 2024

HM Multiple Roles # CVE-2021-24602

CVE, Research URL

CVE-2021-24602

Application

HM Multiple Roles

Date
Aug 23, 2021
Research Description
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low privilege users to set themselves as admin via their profile page
Affected versions
max 1.6.
Status
vulnerable
Nov 15, 2024

HM Multiple Roles # CVE-2022-4974

CVE, Research URL

CVE-2022-4974

Application

HM Multiple Roles

Date
Oct 16, 2024
Research Description
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.6.
Status
vulnerable
Jun 14, 2026

HM Multiple Roles # CVE-2023-33999

CVE, Research URL

CVE-2023-33999

Application

HM Multiple Roles

Date
Jun 11, 2026
Research Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS. This issue affects WP Mail Log: from n/a through 1.0.2.
Affected versions
max 1.9.
Status
vulnerable
Jun 16, 2026

HM Multiple Roles # e0ced8390daf806f54b9f4a1542719af14d54b4a

Application

HM Multiple Roles

Date
Feb 28, 2022
Research Description
HM Multiple Roles [hm-multiple-roles] < 1.6 WordPress HM Multiple Roles plugin < 1.6 - Sensitive Information Disclosure vulnerability Sensitive Information Disclosure vulnerability discovered in WordPress HM Multiple Roles plugin (versions < 1.6).
Affected versions
max 1.6.
Status
vulnerable

HM Multiple Roles # 6d8910c719b2a132ec93828cd37e418b19cac960

Application

HM Multiple Roles

Date
Mar 04, 2022
Research Description
HM Multiple Roles [hm-multiple-roles] < 1.6 Freemius SDK <= 2.4.2 - Missing Authorization Checks The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Affected versions
max 1.6.
Status
vulnerable

HM Multiple Roles # 661d3ede59a4c35b13b428b41eac91ad993f33cf

Application

HM Multiple Roles

Date
Feb 28, 2022
Research Description
HM Multiple Roles [hm-multiple-roles] < 1.6 WordPress HM Multiple Roles plugin < 1.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability discovered in WordPress HM Multiple Roles plugin (versions < 1.6).
Affected versions
max 1.6.
Status
vulnerable