Descripción
El Plugin “Editor de roles de usuario” permite cambiar de manera sencilla los roles y privilegios de los usuarios WordPress.
Tan solo debes activar las casillas de verificación de los privilegios que desee añadir a la función en selección, luego haz clic en el botón “Actualizar” para guardar sus cambios. Y ¡Ya está hecho!
Puedes agregar nuevos roles como también personalizar sus capacidades de acuerdo a sus necesidades, puedes hacerlo desde cero o copiando otro rol existente.
También puedes eliminar roles innecesarios que hayan sido creado por un usuario, siempre y cuando ese rol no se encuentre asociado a un usuario.
Para nuevos usuarios cuyos privilegios son asignados por el sistema de forma predeterminada pueden ser modificados.
Los privilegios pueden ser asignados por usuario. Múltiples roles de forma simultanea también pueden ser asignados a un usuario.
Puedes agregar nuevos privilegios como también eliminar privilegios innecesarios creados por plugins desinstalados.
Se ofrece también soporte para Multi-Sitios.
To read more about ‘User Role Editor’ visit this page
¿Necesita más funcionalidad con soporte de calidad en tiempo real? ¿Desea eliminar anuncios de las páginas del Editor de roles de usuario?
Compra la versión Pro.
User Role Editor Pro incluye módulos adicionales:
- Block selected admin menu items for role.
- Hide selected front-end menu items for no logged-in visitors, logged-in users, roles.
- Block selected widgets under “Appearance” menu for role.
- Show widgets at front-end for selected roles.
- Block selected meta boxes (dashboard, posts, pages, custom post types) for role.
- “Export/Import” module. You can export user role to the local file and import it to any WordPress site or other sites of the multi-site WordPress network.
- Roles and Users permissions management via Network Admin for multisite configuration. One click Synchronization to the whole network.
- “Other roles access” module allows to define which other roles user with current role may see at WordPress: dropdown menus, e.g assign role to user editing user profile, etc.
- Manage user access to editing posts/pages/custom post type using posts/pages, authors, taxonomies ID list.
- Per plugin users access management for plugins activate/deactivate operations.
- Per form users access management for Gravity Forms plugin.
- Shortcode to show enclosed content to the users with selected roles only.
- Posts and pages view restrictions for selected roles.
- Admin back-end pages permissions viewer
Pro version is advertisement free. Premium support is included.
Additional Documentation
You can find more information about “User Role Editor” plugin at this page
I am ready to answer on your questions about plugin usage. Use plugin page comments for that.
Capturas






Instalación
Installation procedure:
- Deactivate plugin if you have the previous version installed.
- Extract “user-role-editor.zip” archive content to the “/wp-content/plugins/user-role-editor” directory.
- Activate “User Role Editor” plugin via ‘Plugins’ menu in WordPress admin menu.
- Go to the “Users”-“User Role Editor” menu item and change your WordPress standard roles capabilities according to your needs.
FAQ
- Does it work with WordPress in multi-site environment?
Yes, it works with WordPress multi-site. By default plugin works for every blog from your multi-site network as for locally installed blog.
To update selected role globally for the Network you should turn on the “Apply to All Sites” checkbox. You should have superadmin privileges to use User Role Editor under WordPress multi-site.
Pro version allows to manage roles of the whole network from the Netwok Admin.
To read full FAQ section visit this page at shinephp.com.
Reseñas
Colaboradores y desarrolladores
«Editor de Perfiles de Usuario» es un software de código abierto. Las siguientes personas han colaborado con este plugin.
Colaboradores«Editor de Perfiles de Usuario» ha sido traducido a 28 idiomas locales. Gracias a los traductores por sus contribuciones.
Traduce «Editor de Perfiles de Usuario» a tu idioma.
¿Interesado en el desarrollo?
Revisa el código , echa un vistazo al repositorio SVN o suscríbete al registro de desarrollo por RSS.
Registro de cambios
[4.66] 19.08.2026
- Update: Marked as compatible with WordPress 7.1
- Required PHP version increased up to 7.4
- Required WordPress version increased up to 4.6
- Update: Plugin loading code is enhanced.
- Update: Plugin does not use self-defined PHP global constants. Needed data moved inside classes.
- Update: URE_Admin_Notice class output was escaped with esc_attr(), wp_kses_post() functions.
- Security Fix: SQL queries in URE_Editor::direct_network_roles_update() and leave_roles_for_blog() are passed to $wpdb->prepare() with real %s placeholders.
- Security Fix: URE_Editor::get_caps_columns_quant() now requires a valid nonce before writing a display-preference transient from $_POST, closing a minor CSRF gap.
- Fix: URE_Protect_Admin used a bitwise “&” instead of a logical “&&” when checking a capabilities array, which could throw a PHP 8 TypeError; fixed to use “&&”, and the related IN() SQL clause is now hardened with array_map(‘absint’, …).
- Update: nonce actions used on the Settings/Tools pages are now scoped per form (ure_settings_update, ure_addons_settings_update, ure_default_roles_update, ure_settings_ms_update, ure_settings_tools_exec) instead of one shared string.
- Update: additional output escaping was added across URE_View, URE_Role_View and URE_Role_Additional_Options (role/capability slugs, wp_json_encode() instead of json_encode(), esc_url() on form actions), plus a defense-in-depth capability check in URE_Role_Additional_Options::save().
- Update: rel=”noopener noreferrer” was added to external links opened with target=”_new”.
- Update: hardcoded text strings in the role editor toolbar are now translatable.
- Fix: URE_Assign_Role used the %i SQL placeholder, which needs WordPress 6.2+, below the plugin’s declared minimum; replaced with direct interpolation of internal table names.
- Fix: URE_Editor::reset_user_roles() had an unescaped wp_die() message; further output escaping (esc_url(), esc_html(), absint()) was added across URE_Base_Lib, URE_Editor, URE_User_Other_Roles and URE_User_View.
- Fix: several request-var/database-result comparisons that could be bypassed by PHP type juggling are now strict, including URE_Grant_Roles::is_try_remove_admin_from_himself()’s “can’t remove your own admin role” check.
- Fix: URE_Base_Lib::set() now correctly rejects unknown properties instead of silently creating them; URE_View declares its $advert property explicitly.
- Update: $_SERVER[‘REQUEST_URI’] is now validated and unslashed before sanitizing in URE_Lib::is_right_admin_path() and URE_User_Other_Roles::is_user_profile_extention_allowed().
- Update: posted role IDs are now sanitized (sanitize_key(), wp_unslash()) in URE_Editor, and its ‘object’/role-selection request parameters are constrained to known values.
- Update: URE_Base_Lib::get_blog_ids() now uses get_sites() instead of a raw database query.
- Update: URE_Capability::revoke_caps() now uses get_users() instead of a raw database query.
- Update: URE_Protect_Admin::has_administrator_role() now uses user_can() instead of a raw database query.
[4.65] 21.05.2026
- Update: Marked as compatible with WordPress 7.0
- Update: Pages markup are modified to correspond WordPress 7.0 CSS changes.
- Update: “defined(‘ABSPATH’)” guard was added to all PHP files to exclude PHP files direct execution.
- Update: sanitize_text_field(), sanitize_key(), sanitize_url() functions are used to secure user input before processing.
- Update: _nonce field checking was added before data update in addition to test made already on the higher level.
File changelog.txt contains the full list of changes.
