Wordpress Alert: Unauthorized role changes

A settings or profile request changes a user's capabilities unexpectedly. An attacker may gain more access or remove a defender's access.

What it looks like

A settings or profile request changes a user's capabilities unexpectedly.

Why it matters

An attacker may gain more access or remove a defender's access.

What to check

Audit role-change events and protect every role update by capability and ownership checks.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities.