CVE-2022-4016
The Booster plugins for WordPress, including Booster, Booster Plus, and Booster Elite, contain a vulnerability that allows attackers to trick administrators into performing malicious actions. Specifically, the plugins fail to properly validate certain functions, making it possible for attackers to create and delete custom roles without proper authentication. This can be exploited through a forged request, such as a link clicked by an administrator, allowing attackers to bypass security checks and gain unauthorized access.
Based on public CVE data (MITRE/NVD).