[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fHPb-yH9PpGH323w8RjfPbjKNtLHcbih-EGfdyxTN5y0":3,"$fqDClVsUtIHjYi7M4FF4SN_Yu_D98k1QLTONEf6bY_CE":166,"$f8D2pJGlqaS7IaoQPR1KWFUkXVtZLwlQxPJq0uBZ3FuE":171},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":11,"last_updated":13,"tested_up_to":14,"requires_at_least":15,"requires_php":16,"tags":17,"homepage":23,"download_link":24,"security_score":25,"vuln_count":26,"unpatched_count":11,"last_vuln_date":27,"fetched_at":28,"discovery_status":29,"vulnerabilities":30,"developer":65,"crawl_stats":36,"alternatives":68,"analysis":36,"fingerprints":36},"highland-software-custom-role-manager","Highland Software Custom Role Manager","1.0.4","jgrodgers","https:\u002F\u002Fprofiles.wordpress.org\u002Fjgrodgers\u002F","\u003Cp>Highland Software Custom Roles Manager extends WordPress role management by allowing administrators to create custom roles, assign multiple roles to users, and manage capabilities through an intuitive interface.\u003C\u002Fp>\n\u003Cp>This plugin follows WordPress best practices for role and capability management, including strict server-side validation and protection against unsafe capability assignment.\u003C\u002Fp>\n\u003Cp>Version 1.0.3 improves role loading, synchronization, and compatibility with third-party plugins by automatically detecting and rendering dynamically registered WordPress roles.\u003C\u002Fp>\n\u003Cp>The plugin now correctly displays existing user roles and automatically detects roles created by third-party plugins such as WooCommerce, LMS platforms, membership systems, CRM integrations, and other custom role providers — without requiring administrators to resave settings.\u003C\u002Fp>\n\u003Ch3>Features\u003C\u002Fh3>\n\u003Cul>\n\u003Cli>Create and manage unlimited custom roles\u003C\u002Fli>\n\u003Cli>Assign multiple roles to a single user\u003C\u002Fli>\n\u003Cli>Automatic detection of third-party and plugin-created roles\u003C\u002Fli>\n\u003Cli>Existing user roles automatically displayed and synchronized\u003C\u002Fli>\n\u003Cli>Group roles for better organization\u003C\u002Fli>\n\u003Cli>Drag-and-drop role ordering\u003C\u002Fli>\n\u003Cli>Capability management with toggle interface\u003C\u002Fli>\n\u003Cli>Role and capability change logging (audit trail)\u003C\u002Fli>\n\u003Cli>Protection against unsafe capability assignment\u003C\u002Fli>\n\u003Cli>Replace the default role dropdown with a checkbox-based interface\u003C\u002Fli>\n\u003Cli>Support for WordPress core roles and custom plugin roles\u003C\u002Fli>\n\u003Cli>Automatic synchronization with newly registered WordPress roles\u003C\u002Fli>\n\u003C\u002Ful>\n","Manage multiple user roles, create custom roles, and control capabilities with an intuitive role builder.",0,634,"2026-06-29T00:33:00.000Z","7.0.2","5.4","7.2",[18,19,20,21,22],"capabilities","permissions","role-manager","user-management","user-roles","https:\u002F\u002Fhighland-software.com\u002Fhighland-software-custom-roles-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhighland-software-custom-role-manager.1.0.4.zip",97,1,"2026-04-26 14:20:30","2026-07-22T17:31:50.256Z","no_bundle",[31],{"id":32,"url_slug":33,"title":34,"description":35,"plugin_slug":4,"theme_slug":36,"affected_versions":37,"patched_in_version":38,"severity":39,"cvss_score":40,"cvss_vector":41,"vuln_type":42,"published_date":27,"updated_date":43,"references":44,"days_to_patch":26,"patch_diff_files":46,"patch_trac_url":36,"research_status":54,"research_verified":55,"research_rounds_completed":56,"research_plan":57,"research_summary":58,"research_vulnerable_code":59,"research_fix_diff":60,"research_exploit_outline":61,"research_model_used":62,"research_started_at":63,"research_completed_at":64,"research_error":36,"poc_status":36,"poc_video_id":36,"poc_summary":36,"poc_steps":36,"poc_tested_at":36,"poc_wp_version":36,"poc_php_version":36,"poc_playwright_script":36,"poc_exploit_code":36,"poc_has_trace":55,"poc_model_used":36,"poc_verification_depth":36},"CVE-2026-7106","highland-software-custom-role-manager-authenticated-subscriber-privilege-escalation","Highland Software Custom Role Manager \u003C= 1.0.0 - Authenticated (Subscriber+) Privilege Escalation","The Highland Software Custom Role Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 1.0.0. This is due to insufficient authorization checks in the hscrm_save_user_roles() function, which is hooked to the personal_options_update action accessible by any authenticated user. This makes it possible for authenticated attackers, with Subscriber-level access or higher, to potentially modify user roles via the profile update form.",null,"\u003C=1.0.0","1.0.1","high",8.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Improper Privilege Management","2026-04-27 02:26:24",[45],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F80a258a6-634c-4d7d-981f-bcbc0bb044f7?source=api-prod",[47,48,49,50,51,52,53],"assets\u002Fjs\u002Fhscrm-events.js","assets\u002Fjs\u002Fhscrm-ui.js","highland-software-custom-role-manager.php","includes\u002Fajax.php","includes\u002Fassets.php","includes\u002Froles.php","includes\u002Fuser-ui.php","researched",false,3,"# Research Plan: Privilege Escalation in Highland Software Custom Role Manager\n\n## Vulnerability Summary\nThe **Highland Software Custom Role Manager** plugin (\u003C= 1.0.0) contains a privilege escalation vulnerability in `includes\u002Fuser-ui.php`. The function `hscrm_save_user_roles()` is hooked to `personal_options_update`, which executes when any user updates their own profile. \n\nThe function performs an insufficient authorization check by verifying `current_user_can('edit_user', $user_id)`. In WordPress, all users (including Subscribers) have the `edit_user` capability for their own User ID. Because the function fails to check for a more restrictive capability (like `promote_users`), it allows any authenticated user to supply an array of roles via the `hscrm_roles[]` parameter, which are then assigned to their account, enabling a Subscriber to promote themselves to Administrator.\n\n## Attack Vector Analysis\n- **Endpoint:** `\u002Fwp-admin\u002Fprofile.php`\n- **Hook:** `personal_options_update`\n- **Required Authentication:** Subscriber or higher.\n- **Vulnerable Parameter:** `hscrm_roles[]`\n- **Security Control Bypassed:** Lack of `promote_users` or `manage_options` check in the save logic.\n\n## Code Flow\n1.  **Entry Point:** User submits the profile update form at `\u002Fwp-admin\u002Fprofile.php`.\n2.  **Hook Trigger:** WordPress triggers `personal_options_update` (for self-updates) or `edit_user_profile_update` (for admin-updates).\n3.  **Function Call:** `hscrm_save_user_roles($user_id)` is executed (`includes\u002Fuser-ui.php`).\n4.  **Auth Check (Weak):** `if (!current_user_can('edit_user', $user_id))` passes because a Subscriber can edit their own profile.\n5.  **Nonce Check:** `wp_verify_nonce(...)` validates `$_POST['hscrm_roles_nonce']` against the action `hscrm_save_user_roles`.\n6.  **Input Processing:** `$_POST['hscrm_roles']` is sanitized using `sanitize_key` but is not validated against the current user's authority to assign those roles.\n7.  **Sink:** The code (truncated in snippet, but inferred) updates the user's roles using `$user->add_role()` or `$user->set_role()` based on the provided list, which includes `administrator`.\n\n## Nonce Acquisition Strategy\nThe `hscrm_roles_nonce` is required for the exploit. This nonce is unique to the authenticated user and can be found in the HTML of the user's own profile page.\n\n1.  Log in as a Subscriber user.\n2.  Navigate to `\u002Fwp-admin\u002Fprofile.php`.\n3.  Locate the hidden input field:\n    `\u003Cinput type=\"hidden\" id=\"hscrm_roles_nonce\" name=\"hscrm_roles_nonce\" value=\"[NONCE_VALUE]\">`\n4.  Also locate the standard WordPress profile nonce `_wpnonce` (action `update-user_{ID}`) required to successfully submit the profile form.\n\n## Exploitation Strategy\n1.  **Preparation:** Use a Subscriber account.\n2.  **Information Gathering:**\n    *   Fetch `\u002Fwp-admin\u002Fprofile.php` and extract:\n        *   `hscrm_roles_nonce`\n        *   `_wpnonce`\n        *   The current user's `user_id` (usually found in the form action or a hidden input).\n3.  **Execution:** Send a POST request to `\u002Fwp-admin\u002Fprofile.php`.\n    *   **Action:** `update`\n    *   **Parameters:**\n        *   `_wpnonce`: extracted standard WP nonce.\n        *   `hscrm_roles_nonce`: extracted plugin nonce.\n        *   `from`: `profile`\n        *   `checkuser_id`: `[your_user_id]`\n        *   `user_id`: `[your_user_id]`\n        *   `nickname`: `attacker` (or any string)\n        *   `email`: `attacker@example.com`\n        *   **`hscrm_roles[]`**: `administrator`\n4.  **Verification:** Check the response for a redirect back to `profile.php?updated=1`.\n\n## Test Data Setup\n1.  **Install Plugin:** Ensure `highland-software-custom-role-manager` version 1.0.0 is active.\n2.  **Create Attacker User:**\n    ```bash\n    wp user create attacker attacker@example.com --role=subscriber --user_pass=password\n    ```\n3.  **Identify ID:**\n    ```bash\n    wp user get attacker --field=ID\n    ```\n\n## Expected Results\nA successful exploit will result in the `attacker` user being assigned the `administrator` role. The plugin's logic for multiple roles may also store these in the `hscrm_custom_roles` user meta, but the immediate WordPress `roles` array should reflect the promotion.\n\n## Verification Steps\nAfter the HTTP request, verify the promotion using WP-CLI:\n```bash\n# Check standard WordPress roles\nwp user get attacker --field=roles\n\n# Check plugin-specific custom meta\nwp user meta get attacker hscrm_custom_roles\n```\n\n## Alternative Approaches\nIf direct promotion to `administrator` is blocked by internal WP filters (unlikely in this context), try promoting to a custom role created by the plugin that has high privileges (if any exist).\n1.  Check for custom roles: `wp role list --fields=role,capabilities`\n2.  If an admin-equivalent custom role exists (e.g., `custom_manager`), use `hscrm_roles[]=custom_manager` instead.","The Highland Software Custom Role Manager plugin (\u003C= 1.0.0) is vulnerable to privilege escalation because the `hscrm_save_user_roles()` function uses a weak capability check. Authenticated users, such as Subscribers, can assign themselves the Administrator role by submitting a profile update request with the `hscrm_roles[]` parameter.","\u002F\u002F includes\u002Fuser-ui.php @ line 220\nadd_action('personal_options_update', 'hscrm_save_user_roles');\nadd_action('edit_user_profile_update', 'hscrm_save_user_roles');\nadd_action('user_register', 'hscrm_save_user_roles');\n\nfunction hscrm_save_user_roles($user_id) {\n\n    \u002F**\n     * SECURITY: Capability check\n     *\u002F\n    if (!current_user_can('edit_user', $user_id)) {\n        return;\n    }","--- includes\u002Fuser-ui.php\n+++ includes\u002Fuser-ui.php\n@@ -224,7 +224,7 @@\n     \u002F**\n      * SECURITY: Capability check\n      *\u002F\n-    if (!current_user_can('edit_user', $user_id)) {\n+    if (!hscrm_user_can_manage_roles()) {\n         return;\n     }","An authenticated attacker with Subscriber-level permissions can escalate their privileges by performing the following steps: \n1. Log in to the WordPress dashboard and navigate to the profile edit page (\u002Fwp-admin\u002Fprofile.php).\n2. Extract the 'hscrm_roles_nonce' value from the hidden input field in the page source and the standard WordPress '_wpnonce' used for profile updates.\n3. Send a POST request to \u002Fwp-admin\u002Fprofile.php with the action 'update', providing the standard nonces and setting the 'hscrm_roles[]' parameter to 'administrator'.\n4. Because the plugin only verifies if the user has the 'edit_user' capability for the targeted ID (which WordPress defaults to true for a user's own profile), the function will process the request and grant the attacker the Administrator role.","gemini-3-flash-preview","2026-04-27 13:28:51","2026-04-27 13:29:29",{"slug":7,"display_name":7,"profile_url":8,"plugin_count":26,"total_installs":11,"avg_security_score":25,"avg_patch_time_days":26,"trust_score":66,"computed_at":67},98,"2026-08-25T00:43:38.240Z",[69,92,115,134,150],{"slug":70,"name":71,"version":72,"author":73,"author_profile":74,"description":75,"short_description":76,"active_installs":77,"downloaded":78,"rating":79,"num_ratings":80,"last_updated":81,"tested_up_to":14,"requires_at_least":82,"requires_php":83,"tags":84,"homepage":87,"download_link":88,"security_score":89,"vuln_count":90,"unpatched_count":11,"last_vuln_date":91,"fetched_at":28},"capability-manager-enhanced","PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus","2.45.0","PublishPress","https:\u002F\u002Fprofiles.wordpress.org\u002Fpublishpress\u002F","\u003Cp>PublishPress Capabilities is the access control plugin for WordPress. You can control all the capabilities and permissions on your WordPress site. We built this user role editor plugin so you have an easy and powerful way to manage user capabilities.\u003C\u002Fp>\n\u003Cp>You can use PublishPress Capabilities to \u003Cstrong>manage all your WordPress user roles\u003C\u002Fstrong>, from Administrators and Editors to Authors, Contributors, Subscribers and custom roles. Each user role can have the exact capabilities that your site needs.\u003C\u002Fp>\n\u003Cp>PublishPress Capabilities can clean up your post editing screen, admin area, and even the Profile screen. You can decide what authors see when they’re writing posts. You can \u003Cstrong>hide any feature on the Gutenberg or Classic Editor screens\u003C\u002Fstrong>. You can remove items in the WordPress dashboard and inside user accounts screens.\u003C\u002Fp>\n\u003Cp>The Pro version of PublishPress Capabilities has many extra features, including the ability to edit admin menu links, clean up the post editing screen, block admin pages by URL, and much more.\u003C\u002Fp>\n\u003Ch3>PublishPress Capabilities Pro\u003C\u002Fh3>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Upgrade to Capabilities Pro\u003C\u002Fstrong>\u003Cbr \u002F>\n  This plugin is the free version of PublishPress Capabilities. The Pro version of Capabilities has all the features you need to control permissions for your WordPress users. With Capabilities Pro you can manage access to posts, pages, media and custom post types. \u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fcapabilities\" title=\"Capabilities Pro\" rel=\"nofollow ugc\">Click here to control access to your WordPress site with Capabilities Pro!\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Ch3>The Key Features of PublishPress Capabilities\u003C\u002Fh3>\n\u003Col>\n\u003Cli>\u003Cstrong>Roles\u003C\u002Fstrong>: You can edit, create, duplicate any WordPress user role.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Capabilities\u003C\u002Fstrong>: You can control all WordPress and plugin capabilities.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Editor Features\u003C\u002Fstrong>: You decide what users see when they’re writing posts in Gutenberg or the Classic Editor.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Features\u003C\u002Fstrong>: You can remove items from the WordPress admin, toolbar, and even dashboard widgets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Styles\u003C\u002Fstrong>: Customize the admin area with your own branding.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Menus (Pro version)\u003C\u002Fstrong>: You can edit admin menu links and control who can access them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Profile Features\u003C\u002Fstrong>: You can hide features for users in the “Profile” screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Redirects\u003C\u002Fstrong>: You can hide features for users in the “Profile” screen.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Frontend Features\u003C\u002Fstrong>: This feature allows you to modify the site’s frontend by hiding or adding CSS.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Navigation Menus\u003C\u002Fstrong>: You can restrict access to navigation menus by user role, or logged in status.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>User Testing\u003C\u002Fstrong>: Safely test any user’s account without resetting their password.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Notices\u003C\u002Fstrong>: Organize all the message and advertisements in your admin area.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch3>Roles\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities gives you detailed control over all the permission levels on your WordPress site. You can edit user roles on your site, from Administrator and Editor to Contributor and Subscriber.\u003C\u002Fp>\n\u003Cp>With PublishPress Capabilities you can create or copy any existing WordPress user role. These roles can be customized in exactly the same way as the default WordPress roles. These new roles can be added to single sites or to an entire multisite network.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fcapabilities-screen\u002F\" rel=\"nofollow ugc\">Click here to see how to manage user roles\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Capabilities\u003C\u002Fh3>\n\u003Cp>With the Capabilities plugin, you can choose who can Publish, Read, Edit and Delete content. You can choose permissions for posts, pages, custom content types, categories, tags, and more.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fpermissions-start\u002F\" rel=\"nofollow ugc\">Click here to see how to manage capabilities\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Many WordPress users have sites with custom post types. This can be done using custom code, a theme, or with a plugin. No matter how your post type is created, PublishPress Capabilities lets you enforce and assign distinct capabilities for your post type.\u003C\u002Fp>\n\u003Cp>PublishPress Capabilities enables you to add extra permissions to the taxonomies on your site. This feature includes the default Categories and Tags, but also applies to other taxonomies. For example, in WooCommerce you can apply custom permissions to Product categories, Product tags, and Product shipping classes. You can enforce and assign “Manage”, “Edit” and “Assign” distinct capabilities for all your taxonomies.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Ftaxonomy-specific-capabilities\u002F\" rel=\"nofollow ugc\">Click here to learn about taxonomy permissions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Editor Features\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities has an option called “Editor Features” allows you to clean up the post editing screen. You can decide what users see when they’re writing posts. You can hide anything on the Gutenberg or Classic Editor screens. You can hide boxes inside the sidebar such Tags, Categories, or Excerpt. You can the “Publish” button. You can even hide the post title, body, or permalink. This is a great alternative to plugins such as Adminimize.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Feditor-features\u002F\" rel=\"nofollow ugc\">Click here to learn about hiding editor features\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>WordPress has a feature called “metaboxes”. This is a strange name, but you have seen them often if you use WordPress. When a user edits a post, the edit screen has several default boxes: Status & visibility, Featured image, Categories, Tags, etc. These boxes are metaboxes. Plugins can add also add their own metaboxes. The Pro version of the PublishPress Capabilities plugin allows you to hide metaboxes for specific user roles.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fhide-metaboxes-in-wordpress-posts\u002F\" rel=\"nofollow ugc\">Click here to learn about hiding metaboxes\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Admin Features\u003C\u002Fh3>\n\u003Cp>Admin Features allows you to hide items in the WordPress admin area and toolbar. You can decide what users see in your WordPress dashboard. You can use this option to hide all the links in the toolbar including “About WordPress”, “Visit Site” and more. You can also hide dashboard widgets such as “At a Glance”, “Quick Draft”, and “WordPress Events and News”.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fadmin-features-screen\u002F\" rel=\"nofollow ugc\">Click here to learn about removing toolbar items and dashboard widgets\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Admin Styles\u003C\u002Fh3>\n\u003Cp>The Admin Styles feature allows you to customize the WordPress admin area with your own branding. You can change the color scheme and visual features for the admin screens. It’s also possible to have different settings for different user roles.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fadmin-styles\u002F\" rel=\"nofollow ugc\">Click here to learn about customizing the admin area with your own branding.\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Admin Menus (Pro version)\u003C\u002Fh3>\n\u003Cp>With PublishPress Capabilities you can edit all your admin menu links. You can also restrict access to admin menu screens by user roles. This is useful because many plugin do not have any way to control who can access their admin screens.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fadmin-menus-screen\u002F\" rel=\"nofollow ugc\">Click to see how to block Admin menu access\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Profile Features\u003C\u002Fh3>\n\u003Cp>“Profile Features” allows you to hide features in the “Profile” screen. You can decide what users see in their accounts.  This “Profile” area is used as a dumping ground for the settings of many different plugins.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fprofile-features\u002F\" rel=\"nofollow ugc\">Click here to learn about the Profile Features option\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Redirects\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities has a “Redirects” screen that allows you to control where users are sent before and after logging in to your site. There are four options available:\u003Cbr \u002F>\n* Login Redirect: Where users are sent when they log in.\u003Cbr \u002F>\n* Logout Redirect: Where users are sent when they log out.\u003Cbr \u002F>\n* Registration Redirect: Where users are sent when they register on your site.\u003Cbr \u002F>\n* First Login Redirect: Where users are sent when they log in to your site for the first time.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fredirects\u002F\" rel=\"nofollow ugc\">Click to see how to redirect users\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Frontend Features\u003C\u002Fh3>\n\u003Cp>The “Frontend Features” screen allows you to modify the features that show on the frontend of your website. You can choose to  hide IDs or classes, add CSS styles, or add body classes. All of these changes can be targeted to specific user roles.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Ffrontend-features\u002F\" rel=\"nofollow ugc\">Click here to learn about frontend changes\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Navigation Menu Restrictions\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities enables you to restrict access to navigation menus by roles, logged in and logged out users. This is useful because a default WordPress site does not give you way to control the visibility of your links.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fnav-menus\u002F\" rel=\"nofollow ugc\">Click to see how to block frontend menu access\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>User Testing \u002F User Switching\u003C\u002Fh3>\n\u003Cp>If you run a WordPress website which allows users to log in, you probably spend a lot of time answering account questions or solving website bugs for your users. Site administrators often have to browse their site and see exactly what the user sees. They need to test the user’s account without resetting their password. This is possible with PublishPress Capabilities.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fuser-testing\u002F\" rel=\"nofollow ugc\">Click here to learn about user testing\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Admin Notices\u003C\u002Fh3>\n\u003Cp>This feature helps organize messages and advertisements in your WordPress admin area. It helps remove clutter from your WordPress experience. This feature will organize all these admin notices into a new area in the top-right corner of your screen. This “Admin Notices” area will show all the notices in a clean, organized area. Nothing is changed about the notices so you can deal with them as normal. The only difference is that you won’t be pestered by these notices on your main admin dashboard.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fadmin-notices-feature\u002F\" rel=\"nofollow ugc\">Click here to learn about Admin Notices\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>PublishPress Capabilities is Safe to Use\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities is completely \u003Cstrong>safe to use\u003C\u002Fstrong>. Every time you change your site’s permissions, this plugin will take a backup that you can restore if anything goes wrong. You can use these backups to migrate your roles and permissions from one site to another.\u003C\u002Fp>\n\u003Cp>This security feature is also very helpful if you want to test out changes on your site, or if you’ve installed a new plugin that has changed your site’s permissions.\u003C\u002Fp>\n\u003Cp>Every time you change your permissions, the PublishPress Capabilities plugin will now automatically create a backup. If you make a mistake, go to the “Backup” menu link and you’ll be able to roll back to a previous version.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fbackup-restore-permissions\u002F\" rel=\"nofollow ugc\">Click here to see how to backup permissions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Support for Media Library Permissions\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities enables you to decide who can upload, edit and delete files from your site’s Media Library. By default, only Administrators are able to delete files in your Media Library. Subscribers and Contributors are not even allowed to upload files. You can customize these permissions for the Media Library and also the Featured Image box.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fcontrol-media-library-access\u002F\" rel=\"nofollow ugc\">Click here to learn about Media Library permissions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Support for WooCommerce Permissions\u003C\u002Fh3>\n\u003Cp>We mentioned earlier that PublishPress Capabilities has special support for WooCommerce taxonomies. This is true for the rest of WooCommerce also. With PublishPress Capabilities you can control permissions for WooCommerce products, orders and coupons.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fwoocommerce-permissons\u002F\" rel=\"nofollow ugc\">Click here to learn about WooCommerce permissions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Support for WordPress Multisite\u003C\u002Fh3>\n\u003Cp>PublishPress Capabilities allows you to control permissions on a single site or across your whole network. Every time you update permissions in PublishPress Capabilities, you can choose to sync those changes across your multisite network.\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fknowledge-base\u002Fmultisite-network\u002F\" rel=\"nofollow ugc\">Click here to learn about multisite permissions\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch3>Join PublishPress and get the Pro plugins\u003C\u002Fh3>\n\u003Cp>The Pro versions of the PublishPress plugins are well worth your investment. The Pro versions have extra features and faster support. \u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fpricing\u002F\" rel=\"nofollow ugc\">Click here to join PublishPress\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Join PublishPress and you’ll get access to these Pro plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fauthors\" rel=\"nofollow ugc\">PublishPress Authors Pro\u003C\u002Fa> allows you to add multiple authors and guest authors to WordPress posts.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fblocks\" rel=\"nofollow ugc\">PublishPress Blocks Pro\u003C\u002Fa> has everything you need to build professional websites with the WordPress block editor.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fcapabilities\" rel=\"nofollow ugc\">PublishPress Capabilities Pro\u003C\u002Fa> is the plugin to manage your WordPress user roles, permissions, and capabilities.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fchecklists\" rel=\"nofollow ugc\">PublishPress Checklists Pro\u003C\u002Fa> enables you to define tasks that must be completed before content is published.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Ffuture\" rel=\"nofollow ugc\">PublishPress Future Pro\u003C\u002Fa> is the plugin for scheduling changes to your posts.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fpermissions\" rel=\"nofollow ugc\">PublishPress Permissions Pro\u003C\u002Fa>  is the plugin for restricted content and advanced WordPress permissions.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fpublishpress\" rel=\"nofollow ugc\">PublishPress Planner Pro\u003C\u002Fa> is the plugin for managing and scheduling WordPress content.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Frevisions\" rel=\"nofollow ugc\">PublishPress Revisions Pro\u003C\u002Fa> allows you to update your published pages with teamwork and precision.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fseries\" rel=\"nofollow ugc\">PublishPress Series Pro\u003C\u002Fa> enables you to group content together into a series.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fshortlinks\" rel=\"nofollow ugc\">PublishPress Shortlinks Pro\u003C\u002Fa> allows you to create custom URLs for your posts and external links.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fpublishpress.com\u002Fstatuses\" rel=\"nofollow ugc\">PublishPress Statuses Pro\u003C\u002Fa> enables you to create additional publishing steps for your posts.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Together, these plugins are a suite of powerful publishing tools for WordPress. If you need to create a professional workflow in WordPress, with moderation, revisions, permissions and more… then you should try PublishPress.\u003C\u002Fp>\n\u003Ch3>Bug Reports\u003C\u002Fh3>\n\u003Cp>Bug reports for PublishPress Capabilities are welcomed in our \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fpublishpress\u002Fpublishpress-capabilities\" rel=\"nofollow ugc\">repository on GitHub\u003C\u002Fa>. Please note that GitHub is not a support forum, and that issues that aren’t properly qualified as bugs will be closed.\u003C\u002Fp>\n","PublishPress Capabilities is the access control plugin. You can manage user capabilities, permissions, user roles, admin menus and more.",100000,4181649,94,143,"2026-06-11T14:20:00.000Z","5.5","7.2.5",[85,18,19,86,22],"admin-menus","user-role-editor","https:\u002F\u002Fpublishpress.com\u002Fcapability-manager\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcapability-manager-enhanced.2.45.0.zip",88,5,"2026-02-20 00:00:00",{"slug":93,"name":94,"version":95,"author":96,"author_profile":97,"description":98,"short_description":99,"active_installs":100,"downloaded":101,"rating":66,"num_ratings":102,"last_updated":103,"tested_up_to":104,"requires_at_least":105,"requires_php":106,"tags":107,"homepage":112,"download_link":113,"security_score":114,"vuln_count":11,"unpatched_count":11,"last_vuln_date":36,"fetched_at":28},"editorial-access-manager","Editorial Access Manager","0.3.2","Taylor Lovett","https:\u002F\u002Fprofiles.wordpress.org\u002Ftlovett1\u002F","\u003Cp>A simple plugin to let you control who has access to what posts. By default in WordPress, we can create users\u003Cbr \u002F>\nand assign them to roles. Roles are automatically assigned certain capabilities. See the codex article for a list of\u003Cbr \u002F>\n\u003Ca href=\"https:\u002F\u002Fcodex.wordpress.org\u002FRoles_and_Capabilities\" rel=\"nofollow ugc\">Roles and Capabilities\u003C\u002Fa>. Sometimes default roles are not enough,\u003Cbr \u002F>\nand we have one-off situations. Editorial Access Manager lets you set which users or roles have access to specific\u003Cbr \u002F>\nposts. Perhaps you have a user who is a Contributor, but you want them to have access to edit one specific page? This\u003Cbr \u002F>\nplugin can help you.\u003C\u002Fp>\n\u003Ch4>Configuration Overview\u003C\u002Fh4>\n\u003Cp>There are no overarching settings for this plugin. Simply go to the edit post screen in the WordPress admin and\u003Cbr \u002F>\nconfigure access settings in the “Editorial Access Manager” meta box in the sidebar.\u003C\u002Fp>\n\u003Ch4>Managing Access by Roles\u003C\u002Fh4>\n\u003Cp>In the “Editorial Access Manager” meta box, enable custom access management by “Roles”. Once enabled, the post can only be\u003Cbr \u002F>\nedited by users that fall into those roles. However, no matter what, the Administrator role can always edit any post.\u003Cbr \u002F>\nThis if for safety reasons. You can also only use roles that have the “edit_posts” capability; therefore “Subscriber” by\u003Cbr \u002F>\ndefault cannot be used.\u003C\u002Fp>\n\u003Ch4>Managing Access by Users\u003C\u002Fh4>\n\u003Cp>In the “Editorial Access Manager” meta box, enable custom access management by “Users”. Once enabled, the post can only be\u003Cbr \u002F>\nedited by designated users. However, no matter what, any administrator can edit any post. This if for safety reasons.\u003Cbr \u002F>\nYou can also only use users that have the “edit_others_posts” capability; therefore “Subscriber” users by default\u003Cbr \u002F>\ncannot be used.\u003C\u002Fp>\n\u003Cp>Fork the plugin on \u003Ca href=\"http:\u002F\u002Fgithub.com\u002Ftlovett1\u002Feditorial-access-manager\" rel=\"nofollow ugc\">Github\u003C\u002Fa>\u003C\u002Fp>\n","Allow for granular editorial access control for all post types in WordPress",80,6506,8,"2017-03-18T19:23:00.000Z","4.9.29","3.6","",[108,109,110,111,22],"editorial-access-management","role-management","user-capabilities","user-permissions","http:\u002F\u002Fwww.taylorlovett.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Feditorial-access-manager.zip",85,{"slug":116,"name":117,"version":118,"author":119,"author_profile":120,"description":121,"short_description":122,"active_installs":123,"downloaded":124,"rating":125,"num_ratings":26,"last_updated":126,"tested_up_to":14,"requires_at_least":127,"requires_php":128,"tags":129,"homepage":132,"download_link":133,"security_score":125,"vuln_count":11,"unpatched_count":11,"last_vuln_date":36,"fetched_at":28},"digages-role-manager","Digages Role Manager – User Roles & Permissions","1.0.0","Timileyin Olabajo","https:\u002F\u002Fprofiles.wordpress.org\u002Ftimleyi\u002F","\u003Cp>\u003Cstrong>Digages Role Manager\u003C\u002Fstrong> is an advanced WordPress role and permission manager for site administrators who need tighter control over what users can see and do inside the dashboard.\u003C\u002Fp>\n\u003Cp>Create custom roles, inherit capabilities from existing WordPress roles, choose which admin menu pages each role can access, and define allowed actions for content, users, plugins, themes, imports, exports, and supported third-party plugins.\u003C\u002Fp>\n\u003Ch4>Key Features\u003C\u002Fh4>\n\u003Cp>\u003Cstrong>Custom Role Creation\u003C\u002Fstrong>\u003Cbr \u002F>\nCreate custom WordPress roles from the admin dashboard. Each role can include a name, description, inherited base role, allowed admin menus, allowed actions, login redirect URL, and admin color scheme.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Menu Restrictions\u003C\u002Fstrong>\u003Cbr \u002F>\nChoose which dashboard menu pages a custom role may access. Restricted menu items are hidden from the WordPress admin area, and direct URL access to blocked pages is redirected.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Action-Level Permissions\u003C\u002Fstrong>\u003Cbr \u002F>\nControl common WordPress actions including creating, editing, deleting, and publishing posts or pages; uploading media; managing comments; managing users; installing, activating, updating, and deleting plugins; managing themes; and importing or exporting data.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>WooCommerce-Aware Controls\u003C\u002Fstrong>\u003Cbr \u002F>\nWhen WooCommerce is active, the plugin adds WooCommerce-specific action controls for orders, products, coupons, reports, settings, and order status changes.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Third-Party Plugin Action Groups\u003C\u002Fstrong>\u003Cbr \u002F>\nThe available action list can automatically include controls for supported plugins when they are active, including Easy Digital Downloads, Advanced Custom Fields, and Gravity Forms.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Unauthorized Action Alerts\u003C\u002Fstrong>\u003Cbr \u002F>\nSet one or more alert email addresses to receive notifications when a restricted action or blocked admin page access attempt occurs.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Audit Log\u003C\u002Fstrong>\u003Cbr \u002F>\nTrack role-related events and blocked access attempts with timestamp, user, action, context, and IP address. The audit log can be filtered and cleared from the admin screen.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Dashboard Overview\u003C\u002Fstrong>\u003Cbr \u002F>\nView quick stats for custom roles, total WordPress roles, audit events, and total users. The dashboard also lists recent audit events and active custom roles.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Role Management Tools\u003C\u002Fstrong>\u003Cbr \u002F>\nEdit, enable, disable, and delete custom roles from a dedicated role management table. Built-in WordPress roles are protected from deletion.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Role-Based Login Redirects\u003C\u002Fstrong>\u003Cbr \u002F>\nSend users with a custom role to a specific URL after login.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Admin Color Scheme Assignment\u003C\u002Fstrong>\u003Cbr \u002F>\nAssign a WordPress admin color scheme per custom role to make role-specific admin experiences easier to identify.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Developer Friendly\u003C\u002Fstrong>\u003Cbr \u002F>\nThe available action groups can be extended with the \u003Ccode>digages_rm_available_actions\u003C\u002Fcode> filter. \u003Ca href=\"https:\u002F\u002Fdigages.com\u002Fcontact\u002F\" rel=\"nofollow ugc\">Contact Developers\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What’s Next?:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cp>If you like this plugin, then consider checking out our other plugins:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdirect-payments-for-woocommerce\u002F\" rel=\"ugc\">Direct Payments for WooCommerce\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdirect-payments-wp\u002F\" rel=\"ugc\">Direct Payments WP\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fdigages.com\u002Fdirect-invoices\u002F\" rel=\"nofollow ugc\">Direct Invoices\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fdigages.com\u002Fengraver-for-woocommerce\u002F\" rel=\"nofollow ugc\">Engraver for WooCommerce\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fsvg-editor\u002F\" rel=\"ugc\">SVG Editor: Upload & Change Colors\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fdigages-restock-alert\u002F\" rel=\"ugc\">Digages Restock Alert\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003Cli>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fauto-pickup-locations-for-woocommerce\u002F\" rel=\"ugc\">APL – Auto-Pickup Locations for WooCommerce\u003C\u002Fa>\u003C\u002Fp>\n\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>Credits\u003C\u002Fh3>\n\u003Cp>Built by Digages.\u003C\u002Fp>\n","Create custom WordPress roles, restrict admin menu access, manage allowed actions, and receive email alerts when restricted actions are attempted.",30,151,100,"2026-07-10T08:11:00.000Z","5.8","7.4",[130,18,19,20,131],"admin-access","roles","https:\u002F\u002Fdigages.com\u002Frole-manager","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fdigages-role-manager.1.0.0.zip",{"slug":135,"name":136,"version":137,"author":138,"author_profile":139,"description":140,"short_description":141,"active_installs":11,"downloaded":142,"rating":11,"num_ratings":11,"last_updated":143,"tested_up_to":14,"requires_at_least":144,"requires_php":128,"tags":145,"homepage":148,"download_link":149,"security_score":125,"vuln_count":11,"unpatched_count":11,"last_vuln_date":36,"fetched_at":28},"adbear-roles-admin-access-manager","AdBear Roles and Admin Access Manager","0.6.3","Secil Kars","https:\u002F\u002Fprofiles.wordpress.org\u002Fsecilkars\u002F","\u003Cp>AdBear Roles and Admin Access Manager helps site owners and agencies control what each WordPress user role can see and do in the admin area — without writing custom code.\u003C\u002Fp>\n\u003Cp>Use one admin menu to:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Create, edit, clone, and delete custom roles\u003C\u002Fli>\n\u003Cli>Assign built-in and custom capabilities\u003C\u002Fli>\n\u003Cli>Hide admin menus and block direct URL access to hidden pages\u003C\u002Fli>\n\u003Cli>Control dashboard widgets and admin bar items by role\u003C\u002Fli>\n\u003Cli>Set login redirect URLs after sign-in\u003C\u002Fli>\n\u003Cli>Limit Advanced Custom Fields (ACF) field groups by role\u003C\u002Fli>\n\u003Cli>Customize the wp-login screen (logo, colors, layout)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The administrator role is always protected and cannot be edited or deleted through this plugin.\u003C\u002Fp>\n\u003Cp>This plugin does not handle front-end membership or user registration forms. It focuses on admin access control and login branding.\u003C\u002Fp>\n\u003Ch3>Getting started\u003C\u002Fh3>\n\u003Cp>All settings are under \u003Cstrong>AdBear Roles\u003C\u002Fstrong> in the WordPress admin. You need the \u003Ccode>manage_options\u003C\u002Fcode> capability (typically an Administrator).\u003C\u002Fp>\n\u003Ch4>Step 1: Roles & Capabilities\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Roles & Capabilities\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>To add a role, enter a \u003Cstrong>Role key\u003C\u002Fstrong> (lowercase, no spaces, e.g. \u003Ccode>shop_manager\u003C\u002Fcode>) and a \u003Cstrong>Role label\u003C\u002Fstrong> (display name).\u003C\u002Fli>\n\u003Cli>Check the capabilities the role should have, or add custom capability names in the text field.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save role\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>To copy an existing role, use \u003Cstrong>Clone role\u003C\u002Fstrong> and provide a new key and label.\u003C\u002Fli>\n\u003Cli>To change the role assigned to new registrations, pick a role under \u003Cstrong>Default registration role\u003C\u002Fstrong> and click \u003Cstrong>Save default role\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Step 2: Admin menu visibility\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Admin Menu Visibility\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Select the role from the dropdown.\u003C\u002Fli>\n\u003Cli>Enable \u003Cstrong>Enable menu restrictions for this role\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Check only the menu items that role should see.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save menu rules\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>Hidden menus are removed from the sidebar. If a user visits a hidden page by URL, access is denied.\u003C\u002Fp>\n\u003Ch4>Step 3: Dashboard widgets\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Dashboard Widgets\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Select the role, enable restrictions, and check the widgets to keep visible.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save dashboard rules\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Step 4: Admin bar\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Admin Bar\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Select the role, enable restrictions, and check the admin bar items to keep.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save admin bar rules\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Step 5: Login redirects\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Login Redirects\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Enter an internal URL for each role that should redirect after login (leave blank to use WordPress default).\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save redirects\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Step 6: ACF field groups (optional)\u003C\u002Fh4>\n\u003Cp>Requires the Advanced Custom Fields plugin.\u003C\u002Fp>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> ACF Group Visibility\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Select the role, enable restrictions, and check the field groups to show.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save ACF rules\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch4>Step 7: Login & branding\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Go to \u003Cstrong>AdBear Roles \u003Cspan aria-hidden=\"true\" class=\"wp-exclude-emoji\">→\u003C\u002Fspan> Login & Branding\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003Cli>Enable branding, then set logo, background, button color, layout, and optional admin footer text.\u003C\u002Fli>\n\u003Cli>Click \u003Cstrong>Save branding settings\u003C\u002Fstrong>.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>To test, log out and open your site’s \u003Ccode>wp-login.php\u003C\u002Fcode> page, or log in as a user with the role you configured.\u003C\u002Fp>\n","Manage WordPress roles, admin menus, dashboard widgets, login redirects, ACF access, and wp-login branding by user role.",136,"2026-06-24T14:34:00.000Z","6.0",[146,18,19,22,147],"admin-menu","wp-login","https:\u002F\u002Fwordpressplugin.adbear.cloud\u002Fadbear-roles-and-admin-access-manager\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadbear-roles-admin-access-manager.0.6.3.zip",{"slug":151,"name":152,"version":38,"author":153,"author_profile":154,"description":155,"short_description":156,"active_installs":11,"downloaded":157,"rating":11,"num_ratings":11,"last_updated":158,"tested_up_to":14,"requires_at_least":159,"requires_php":160,"tags":161,"homepage":164,"download_link":165,"security_score":125,"vuln_count":11,"unpatched_count":11,"last_vuln_date":36,"fetched_at":28},"advanced-user-role-manager","Advanced User Role Manager","Smackcoders Inc.,","https:\u002F\u002Fprofiles.wordpress.org\u002Fsmackcoders\u002F","\u003Cp>Advanced User Role Manager is a comprehensive solution for managing WordPress user roles and capabilities, crafted by experienced human developers. This plugin extends WordPress’s default role system with advanced features for better user access control, designed with real-world use cases in mind.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Custom Role Management\u003C\u002Fstrong>: Create, edit, clone, and delete custom user roles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Temporary Role Assignments\u003C\u002Fstrong>: Assign roles with automatic expiration\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Granular Capability Control\u003C\u002Fstrong>: Manage specific permissions for each role\u003C\u002Fli>\n\u003Cli>\u003Cstrong>OAuth2 Integration\u003C\u002Fstrong>: Secure login with external providers\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Role-Based User Filtering\u003C\u002Fstrong>: Filter and manage users by their roles\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit Logging\u003C\u002Fstrong>: Track all role-related changes for security\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Multi-Role Support\u003C\u002Fstrong>: Assign multiple roles to individual users\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Use Cases:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Membership sites requiring different access levels\u003C\u002Fli>\n\u003Cli>Multi-author blogs with varying permissions\u003C\u002Fli>\n\u003Cli>E-commerce sites with customer and staff roles\u003C\u002Fli>\n\u003Cli>Corporate websites with role-based access control\u003C\u002Fli>\n\u003Cli>Educational platforms with student and teacher roles\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>Compatibility:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Works with WooCommerce and other e-commerce plugins\u003C\u002Fli>\n\u003Cli>Compatible with membership plugins\u003C\u002Fli>\n\u003Cli>Supports custom post types\u003C\u002Fli>\n\u003Cli>Built following WordPress coding standards\u003C\u002Fli>\n\u003C\u002Ful>\n","Advanced WordPress user role management with custom roles, temporary assignments, and OAuth2 integration.",541,"2026-04-22T10:47:00.000Z","6.8","7.0",[162,18,109,21,163],"advanced-user-role","user-role-manager","https:\u002F\u002Fwww.smackcoders.com","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fadvanced-user-role-manager.1.0.1.zip",{"error":167,"url":168,"statusCode":169,"statusMessage":170,"message":170},true,"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fhighland-software-custom-role-manager\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":90,"versions":172},[173,178,185,192,198],{"version":6,"download_url":24,"svn_tag_url":174,"released_at":36,"has_diff":55,"diff_files_changed":175,"diff_lines":36,"trac_diff_url":176,"vulnerabilities":177,"is_current":167},"https:\u002F\u002Fplugins.svn.wordpress.org\u002Fhighland-software-custom-role-manager\u002Ftags\u002F1.0.4\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.3&new_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.4",[],{"version":179,"download_url":180,"svn_tag_url":181,"released_at":36,"has_diff":55,"diff_files_changed":182,"diff_lines":36,"trac_diff_url":183,"vulnerabilities":184,"is_current":55},"1.0.3","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhighland-software-custom-role-manager.1.0.3.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fhighland-software-custom-role-manager\u002Ftags\u002F1.0.3\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.2&new_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.3",[],{"version":186,"download_url":187,"svn_tag_url":188,"released_at":36,"has_diff":55,"diff_files_changed":189,"diff_lines":36,"trac_diff_url":190,"vulnerabilities":191,"is_current":55},"1.0.2","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhighland-software-custom-role-manager.1.0.2.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fhighland-software-custom-role-manager\u002Ftags\u002F1.0.2\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.1&new_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.2",[],{"version":38,"download_url":193,"svn_tag_url":194,"released_at":36,"has_diff":55,"diff_files_changed":195,"diff_lines":36,"trac_diff_url":196,"vulnerabilities":197,"is_current":55},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhighland-software-custom-role-manager.1.0.1.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fhighland-software-custom-role-manager\u002Ftags\u002F1.0.1\u002F",[],"https:\u002F\u002Fplugins.trac.wordpress.org\u002Fchangeset?old_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.0&new_path=%2Fhighland-software-custom-role-manager%2Ftags%2F1.0.1",[],{"version":118,"download_url":199,"svn_tag_url":200,"released_at":36,"has_diff":55,"diff_files_changed":201,"diff_lines":36,"trac_diff_url":36,"vulnerabilities":202,"is_current":55},"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fhighland-software-custom-role-manager.1.0.0.zip","https:\u002F\u002Fplugins.svn.wordpress.org\u002Fhighland-software-custom-role-manager\u002Ftags\u002F1.0.0\u002F",[],[203],{"id":32,"url_slug":33,"title":34,"severity":39,"cvss_score":40,"vuln_type":42,"patched_in_version":38}]