CVE-2026-7106 | jgrodgers Highland Software Custom Role Manager Plugin up to 1.0.0 on WordPress Profile Page hscrm_save_user_roles privileges management
A vulnerability, which was classified as critical, was found in jgrodgers Highland Software Custom Role Manager Plugin up to 1.0.0 on WordPress. Impacted is the function hscrm_save_user_roles of the component Profile Page Handler. The manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-7106. It is possible to launch the attack remotely. No exploit is available.