CPE
An improper authorization vulnerability in the Groups - Memberships and Access Control WordPress plugin allows authenticated subscribers to escalate privileges by manipulating group enrollment context.