What the vulnerability does
01Description
Incorrect Privilege Assignment vulnerability in madiriaashish Adding drop down roles in registration user-drop-down-roles-in-registration allows Privilege Escalation.This issue affects Adding drop down roles in registration: from n/a through <= 1.1.
Explanation of Vulnerability in Simple Terms
02Summary
A privilege escalation vulnerability in the 'Adding drop down roles in registration' component allows unauthenticated attackers to gain administrative access without user interaction. The flaw stems from improper privilege validation during user registration. All versions up to 1.1 are affected. No patched version is currently available.
What an attacker can do
03Attacker Capabilities
Gain full administrative access to the site without authentication.
Potential impact on your site
04Site Impact
An attacker can take complete control of your site, modify content, create accounts, and access all data.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
October 17, 2024
CVE published
April 29, 2026
Record updated