CVE-2026-7106Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-27); latest day: 1
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-27: 4Mentions · 2026-04-28: 1Mentions · 2026-06-04: 1PoC Mentioned / Linked · 2026-04-28: 1Technical Details · 2026-04-27: 4Technical Details · 2026-04-28: 1Technical Details · 2026-06-04: 104-2704-2806-04
Signal classification3 categories
Disclosure
466.7%
General
116.7%
PoC
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-274
Disclosure3General1
2026-04-281
PoC1
2026-06-041
Disclosure1
Full discourse6 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-7106 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-7106 #CVE-2026-7106 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/ibjgp8ykrE

    Post summary

    The tweet announces a new high‑severity WordPress vulnerability (CVE‑2026‑7106) specifying its CVSS score, but does not provide any exploit details, PoC, or patch information.

    01022136
    158 followersView on X
  • Joey Romaine 🇺🇸 |=★=|@Tank23x0
    Disclosure

    New advisory to triage: CVE-2026-7106. The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including… Inventory first. Panic never helps.

    Post summary

    An advisory announces a privilege‑escalation flaw (CVE-2026-7106) in the Highland Software Custom Role Manager WordPress plugin; no patch, exploit, or active‑exploitation details are included.

    1000039
    309 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-7106-highland-software-custom-role-manager-version-1-0-0-high-vulnerability-proof-of-concept CVE-2026-7106 highland-software-custom-role-manager (CVSS Score 8.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpr…

    Post summary

    A proof‑of‑concept for CVE‑2026‑7106 in Highland Software Custom Role Manager has been published, highlighting its high severity (CVSS 8.8) and providing a link to the PoC.

    0000055
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7106 The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient … https://www.cve.org/CVERecord?id=CVE-2026-7106

    Post summary

    CVE-2026-7106 reveals a privilege‑escalation flaw in the Highland Software Custom Role Manager WordPress plugin up to version 1.0.0; no exploit, patch, or PoC is provided.

    0000098
    57.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-7106 Privilege Escalation in Highland Software Custom Role Manager Word... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7106 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet briefly announces CVE-2026-7106, indicating a privilege‑escalation flaw in Highland Software’s Custom Role Manager, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000064
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-7106 The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to … CVSS 8.8 Full analysis → https://sec.kaitan.id/cves/CVE-2026-7106 #WordPress #CyberSecurity #InfoSec

    Post summary

    Highlights the announcement of a high‑severity privilege escalation vulnerability (CVE‑2026‑7106) in the Highland Software Custom Role Manager plugin for WordPress, providing CVSS 8.8 but no exploit or patch details.

    0000042
    142 followersView on X

Explore more