ProfilePress plugin before 3.1.4 allows privilege escalation. Due to insufficient validation in the profile update functionality, authenticated users can supply arbitrary usermeta fields, including `wp_capabilities`, during profile updates. This enables a user to escalate their privileges to administrator.
id: CVE-2021-34622
info:
name: WordPress ProfilePress <= 3.1.3 - Privilege Escalation
author: S
...