CVE-2023-4404 | Charitable Donation Forms Plugin up to 1.7.0.12 on WordPress update_core_user role privileges management
A vulnerability categorized as critical has been discovered in Charitable Donation Forms Plugin up to 1.7.0.12 on WordPress. The affected element is the function update_core_user. The manipulation of the argument role results in improper privilege management.
This vulnerability is reported as CVE-2023-4404. The attack can be launched remotely. No exploit exists.