CyberRota Analysis
AI-GeneratedThe Add User Autocomplete plugin for WordPress versions prior to 1.2 is vulnerable as it lacks proper capability and nonce checks, enabling any authenticated user to create a pending site-membership invitation with elevated privileges, including the administrator role. This vulnerability poses a significant risk to multisite installations, as it allows unauthorized users to gain administrative access, potentially compromising the entire network. WordPress administrators and security teams should prioritize this issue to mitigate the risk of privilege escalation.
Original NVD Description
The Add User Autocomplete WordPress plugin before 1.2 does not perform any capability or nonce check before creating a pending site-membership invitation carrying a caller-supplied role, allowing any authenticated user, such as a subscriber, to grant themselves the administrator role on a multisite installation.