[Plugin: User Role Editor] Editor can Edit Admin!!
-
Hi there,
Thanks for version 2, but still there is a security hole:I gave Editor ability to see & edit users
When I edit user, this is the url:
/wp-admin/user-edit.php?user_id=20&wp_http_referer=/wp-admin/users.phpIf I change the user_id from 20 to 1 (the admin id) I can edit the admin user level and set it to editor and below.
Viewing 9 replies - 1 through 9 (of 9 total)
Viewing 9 replies - 1 through 9 (of 9 total)
- The topic ‘[Plugin: User Role Editor] Editor can Edit Admin!!’ is closed to new replies.