User Role Editor Plugin Finally Checks Whether User Has Role to Edit User Roles
Security update introduces radical new authorization technology known as “making sure the request came from the fucking administrator.”
INTERNET — The developers of User Role Editor released version 4.66 this week after discovering that their plugin for meticulously controlling what every WordPress user is allowed to do had occasionally neglected the minor formality of checking who the hell was doing it.
The update adds nonce verification, output escaping, and properly prepared SQL queries—three obscure security techniques collectively known as “the shit the plugin should have been doing before it was installed on 700,000 websites.”
“We built an advanced permissions system capable of distinguishing among administrators, editors, authors, contributors, and subscribers,” said one developer. “Unfortunately, our database queries recognized only two roles: %s and good luck.”
Before the update, User Role Editor could define thousands of granular capabilities, ensuring a junior employee could upload an image but not install plugins, edit another user’s posts, or accidentally destroy the company website.
Whether an incoming request was legitimate, however, was apparently left to the honor system.
The plugin’s new nonce requirement means WordPress will now verify that certain changes were intentionally requested by an authorized user instead of accepting commands from whichever malicious webpage happened to shout them through an open window.
Administrators are strongly encouraged to update immediately, then spend 45 minutes confirming that the patch did not revoke their own permissions and promote an abandoned Mailchimp integration to Super Admin.
At press time, User Role Editor was reportedly preparing version 4.67, which will introduce another groundbreaking access-control feature: the door will be locked when nobody is home.
