Cyber Resilience

CVE-2023-1874

HighPublic PoC

Published: 12 April 2023

Published
12 April 2023
Modified
08 April 2026
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0626 91.1th percentile
Risk Priority 19 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2023-1874 is a high-severity Incorrect Privilege Assignment (CWE-266) vulnerability in Wpdataaccess Wp Data Access. Its CVSS base score is 7.5 (High).

Operationally, ranked in the top 8.9% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

Deeper analysis

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to and including 5.3.7. The flaw arises from missing authorization checks on the multiple_roles_update function in WPDA_Roles.php, which becomes reachable when the site's "Enable role management" setting is turned on.

Authenticated attackers holding minimal privileges, such as a subscriber account, can exploit the issue by supplying the wpda_role[] parameter while performing a profile update, thereby assigning themselves elevated roles and obtaining administrative capabilities.

The vulnerability was fixed in version 5.3.8, where the referenced code path was updated to enforce authorization. Public advisories from Wordfence note that the plugin developers released the patch promptly after the issue was identified.

The associated EPSS score has remained flat at 0.0626 with no material rise since disclosure.

EU & UK References

Vulnerability details

The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 5.3.7. This is due to a lack of authorization checks on the multiple_roles_update function. This makes it possible for authenticated attackers, with…

more

minimal permissions such as a subscriber, to modify their user role by supplying the 'wpda_role[]' parameter during a profile update. This requires the 'Enable role management' setting to be enabled for the site.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

wpdataaccess
wp data access
≤ 5.3.7

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-266

Designation of a manager and policy dissemination ensures privileges are assigned according to defined roles.

addresses: CWE-266

Regular reviews catch incorrect privilege assignments to users, roles, or processes.

addresses: CWE-266

Explicitly specifying privileges and group/role memberships for accounts reduces the risk of incorrect privilege assignments.

addresses: CWE-266

The control requires explicit definition of separated access authorizations, making incorrect privilege assignments that bundle conflicting duties harder to implement.

addresses: CWE-266

Ensures privileges are assigned only as necessary rather than incorrectly over-granted.

References