User Role Editor

Descrizione

Il plugin di WordPress User Role Editor permette di cambiare i ruoli e le capacità degli utenti in maniera semplice.
Ti basta spuntare le checkbox delle capacità che desideri aggiungere al ruolo selezionato e fare clic sul pulsante “Aggiorna” per salvare le modifiche. Ecco fatto.
Aggiungi nuovi ruoli e personalizzane le capacità in base alle tue esigenze, sia da zero che come copia di un altro ruolo esistente.
I ruoli non più necessari possono essere eliminati se non ci sono più utenti a cui tale ruolo è assegnato.
Anche il ruolo assegnato per impostazione predefinita alla creazione di nuovi utenti può essere modificato.
Le capacità possono essere assegnate sulla base del singolo utente. Ruoli multipli possono essere assegnati agli utenti simultaneamente.
Puoi aggiungere nuove capacità e rimuovere le capacità non più necessarie che potrebbero essere rimasugli di plugin disinstallati.
La modalità multi-sito è supportata.

To read more about ‘User Role Editor’ visit this page

Hai bisogno di maggiori funzionalità con un supporto di qualità in tempo reale? Vuoi rimuovere la pubblicità dalle pagine di User Role Editor?
Acquista la versione Pro.
User Role Editor Pro include i moduli extra:

  • Blocco delle voci di menu di amministrazione selezionate in base al ruolo.
  • Rimozione delle voci di menu del front-end selezionate per i visitatori non autenticati, quelli autenticati e per quelli con ruoli specifici.
  • Blocco dei widget selezionati nel menu “Aspetto” in base al ruolo.
  • Mostra i widget nel front-end per i ruoli selezionati.
  • Blocco dei meta box selezionati (bacheca, articoli, pagine, contenuti personalizzati) in base al ruolo.
  • Modulo “Esporta/Importa”. Puoi esportare i ruoli utente in un file locale ed importarli in un qualunque sito WordPress o su altri siti della rete WordPress multi-sito.
  • Gestione delle autorizzazioni per ruoli e utenti tramite il pannello di gestione di rete per le installazioni multi-sito. Sincronizzazione in un click sull’intera rete.
  • Il modulo “Accesso ad altri ruoli” permette di definire quali altri ruoli un utente può vedere in base al proprio ruolo su WordPress nei menu a discesa, es. quando si assegna un ruolo in fase di modifica del profilo di un utente, etc.
  • Gestisci l’accesso degli utenti alla modifica di articoli/pagine/custom post type utilizzando liste di ID di articoli/pagine, autori, tassonomie.
  • Gestione di accesso degli utenti in base ai singoli plugin per operazioni di attivazione/disattivazione.
  • Gestione di accesso degli utenti in base ai singoli form per il plugin Gravity Forms.
  • Shortcode per mostrare il contenuto incluso solo agli utenti con i ruoli selezionati.
  • Restrizione della visualizzazione di articoli e pagine per i ruoli selezionati.
  • Visualizzazione delle autorizzazioni di accesso al back-end

La versione Pro è senza pubblicità. È incluso il supporto Premium.

Documentazione Aggiuntiva

Puoi trovare maggiori informazioni sul plugin “User Role Editor” in questa pagina

Sono pronto a rispondere alle tue domande sull’uso del plugin. Usa la pagina dei commenti del plugin a questo scopo.

Screenshot

Installazione

Procedura di installazione:

  1. Disattiva il plugin se hai la versione precedente installata.
  2. Estrai il contenuto dell’archivio “user-role-editor.zip” nella directory “/wp-content/plugins/user-role-editor”.
  3. Activate “User Role Editor” plugin via ‘Plugins’ menu in WordPress admin menu.
  4. Vai al menu “Utenti”-“User Role Editor” e modifica la capacità standard di WordPress in base alle tue necessità.

FAQ

  • Funziona con la modalità multi-sito di WordPress?
    Sì, la modalità multi-sito di WordPress è supportata. Per impostazione predefinita il plugin funziona per tutti i blog facenti parte dell’installazione multi-sito.
    Per aggiornare il ruolo selezionato sull’intera rete multi-sito devi spuntare la checkbox “Applica a tutti i siti”. Occorre avere i privilegi di super-amministratore per poter utilizzare User Role Editor su un’installazione multi-sito.
    La versione Pro permette di gestire i ruoli dell’intera rete dalle impostazioni di amministrazione di rete.

Per leggere le FAQ visita questa pagina su shinephp.com.

Recensioni

24 Luglio 2026
If you need to manage custom roles or tweak specific capabilities for your clients, look no further. User Role Editor is lightweight, perfectly integrated into the WordPress core logic, and extremely reliable. It allows us to restrict client access safely without breaking site functionality. A 5-star, must-have plugin for any serious development environment.
25 Giugno 2025
This plugin is working well. Thank you for the developer who put lot of time into it. Very nice, lightest and most simple.
22 Aprile 2025
I'm a DIY self learner, and had a great experience with URE. It has vast capabilities and is organized to make it easy to navigate and apply so many customizations. Very intuitive. On the one occasion I needed guidance, the tech support was quick, personal and a success. Highly recommend.
16 Aprile 2025
I hate giving bad reviews as I know how much work goes into these plugins, often by one person. But we have wasted so much time and lost orders because of a known bug. I can see that others have reported this bug from at least 4 months ago. So I want to warn others. The whole point of us using this plugin was to create a custom role and to assign specific capabilities to that role. For a short while it worked so we launched the site. And then it stopped working and caused chaos. We have spent FOREVER trying to figure this out. We will be moving to a different plugin asap.
27 Marzo 2025
Didn't break my site, it just doesn't work. On multisite, trying to give user permissions to install plugins–as it indicated in settings that it could do that. Appears to uninstall cleanly, at least.
Leggi tutte le recensioni di 288

Contributi e sviluppo

“User Role Editor” è un software open source. Le persone che hanno contribuito allo sviluppo di questo plugin sono indicate di seguito.

Collaboratori

“User Role Editor” è stato tradotto in 30 lingue. Grazie a chi traduce per il contributo.

Traduci “User Role Editor” nella tua lingua.

Ti interessa lo sviluppo?

Esplora il codice segui il repository SVN, segui il log delle modifiche tramite RSS.

Changelog

[4.66.2] 25.09.2026

  • Security Fix: administrator-role protection (URE_Protect_Admin::exclude_admin_role()) only excluded the “administrator” role from the assignable-roles list on the classic user edit screens, not on the plugin’s own admin-ajax.php actions; a user holding the “promote_users” capability (without the plugin’s own key capability) could therefore grant themselves or another user the “administrator” role via the “Add Role”/”Grant Roles” AJAX action, bypassing the same protection the classic Users screen correctly enforced. Discovered and responsibly reported by Humberto (SVO, https://svo.com.br).
  • Fix: the “Grant Roles” dialog’s AJAX request (get_grant_roles) incorrectly required the plugin’s own key capability instead of “promote_users”, refusing users who only had “promote_users” – the capability the Grant Roles feature is designed for – with an “Insufficient permissions” error.
  • Fix: “Add Role” dialog kept showing the previously entered Role name (ID) and Display Role Name after a role was added, instead of blank fields.
  • Fix: opening a user’s edit-profile screen and leaving without making any changes could show a spurious “Changes you made may not be saved” browser warning whenever the user had any “Other Roles” assigned; the Other Roles multi-select now renders its selected options directly in HTML instead of relying on JavaScript to select them after page load.
  • Update: “Delete Role” dialog now lists deletable roles in a checkbox table (Role Name / Role ID columns) instead of a single-select dropdown, so multiple roles can be deleted in one action; the old “Delete All Unused Roles” option is replaced by a “select all” checkbox in the table header.
  • Update: “Delete Capability” dialog now has a “Quick Filter” text field next to its “select all” checkbox, to narrow down the capability list the same way the main page’s “Quick filter” field does.
  • Update: The multisite “Allow non super administrators to create, edit, and delete users” option is narrowed to “Allow non super administrators to edit users”. The “create” part duplicated WordPress core’s own “Allow site administrators to add new users to their site via the ‘Users -> Add User’ page” network setting, and the “delete” part granted a capability that WordPress core never actually lets a single site administrator exercise (user deletion is blocked outside Network Admin regardless of capability) – both are dropped, along with the temporary superadmin-impersonation workaround they relied on.
  • Update: Plugin’s own JavaScript files (ure.js, settings.js, users.js, user-profile-other-roles.js, users-grant-roles.js) now have minified .min.js builds, generated with esbuild; each is enqueued via WordPress’s SCRIPT_DEBUG constant, same convention already used for the vendored notify.js/multiple-select.js (unminified source when SCRIPT_DEBUG is on, minified build otherwise).
  • Update: Plugin’s own CSS (css/ure-admin.css) now has a minified .min.css build, generated with esbuild; it’s enqueued via WordPress’s SCRIPT_DEBUG constant, same convention already used for the plugin’s own JS files (unminified source when SCRIPT_DEBUG is on, minified build otherwise).
  • Update: js/users-grant-roles.js’s loose global functions (Grant Roles dialog, Add/Revoke role buttons on the Users page) were consolidated into a single URE_Users_Grant_Roles object.
  • Update: Replaced the deprecated jQuery .click()/.click(fn) event-binding shorthand with .on(‘click’, fn) in users-grant-roles.js and users.js, clearing a jQuery Migrate deprecation warning on the Users page.
  • Update: js/users.js’s loose global functions (the “Without role” button’s dialog on the Users page) were consolidated into a single URE_No_Role_Users object; the button’s onclick markup in URE_Assign_Role::show_html() was updated to match.
  • Update: js/user-profile-other-roles.js’s loose global functions (the user profile “Other Roles” multi-select control) were consolidated into a single URE_User_Profile_Other_Roles object.
  • Update: js/settings.js’s loose global functions (the Settings page’s “Reset User Roles” confirmation dialog) were consolidated into a single URE_Settings object.

[4.66.1] 25.08.2026

  • Fix: URE_Assign_Role::$lib property was changed to protected.
  • Fix: URE_Uninstall::delete_options() private function changed to protected.
  • Fix: URE_Uninstall::init_options_list() referenced ‘ure_task_queue’, which never matched URE_Task_Queue::OPTION_NAME (‘ure_tasks_queue’), so that option was never deleted on uninstall.
  • Fix: URE_Core::define_files() – class URE_Uninstall was not added correctly, null was written instead of class name.
  • Fix: activating Pro while free was already active caused a fatal “Cannot redeclare ure_log_error()” error; the function declaration is now guarded with function_exists().
  • Fix: activating this plugin while the paired Pro plugin was already active silently left both active instead of deactivating the paired one, because the register_activation_hook() call never ran in that request; it’s now registered as a standalone function directly in the main plugin file, ahead of the class_exists(‘URE_Loader’) guard that was skipping it.

[4.66] 19.08.2026

  • Update: Marked as compatible with WordPress 7.1
  • Required PHP version increased up to 7.4
  • Required WordPress version increased up to 4.6
  • Update: Plugin loading code is enhanced.
  • Update: Plugin does not use self-defined PHP global constants. Needed data moved inside classes.
  • Update: URE_Admin_Notice class output was escaped with esc_attr(), wp_kses_post() functions.
  • Security Fix: SQL queries in URE_Editor::direct_network_roles_update() and leave_roles_for_blog() are passed to $wpdb->prepare() with real %s placeholders.
  • Security Fix: URE_Editor::get_caps_columns_quant() now requires a valid nonce before writing a display-preference transient from $_POST, closing a minor CSRF gap.
  • Fix: URE_Protect_Admin used a bitwise “&” instead of a logical “&&” when checking a capabilities array, which could throw a PHP 8 TypeError; fixed to use “&&”, and the related IN() SQL clause is now hardened with array_map(‘absint’, …).
  • Update: nonce actions used on the Settings/Tools pages are now scoped per form (ure_settings_update, ure_addons_settings_update, ure_default_roles_update, ure_settings_ms_update, ure_settings_tools_exec) instead of one shared string.
  • Update: additional output escaping was added across URE_View, URE_Role_View and URE_Role_Additional_Options (role/capability slugs, wp_json_encode() instead of json_encode(), esc_url() on form actions), plus a defense-in-depth capability check in URE_Role_Additional_Options::save().
  • Update: rel=”noopener noreferrer” was added to external links opened with target=”_new”.
  • Update: hardcoded text strings in the role editor toolbar are now translatable.
  • Fix: URE_Assign_Role used the %i SQL placeholder, which needs WordPress 6.2+, below the plugin’s declared minimum; replaced with direct interpolation of internal table names.
  • Fix: URE_Editor::reset_user_roles() had an unescaped wp_die() message; further output escaping (esc_url(), esc_html(), absint()) was added across URE_Base_Lib, URE_Editor, URE_User_Other_Roles and URE_User_View.
  • Fix: several request-var/database-result comparisons that could be bypassed by PHP type juggling are now strict, including URE_Grant_Roles::is_try_remove_admin_from_himself()’s “can’t remove your own admin role” check.
  • Fix: URE_Base_Lib::set() now correctly rejects unknown properties instead of silently creating them; URE_View declares its $advert property explicitly.
  • Update: $_SERVER[‘REQUEST_URI’] is now validated and unslashed before sanitizing in URE_Lib::is_right_admin_path() and URE_User_Other_Roles::is_user_profile_extention_allowed().
  • Update: posted role IDs are now sanitized (sanitize_key(), wp_unslash()) in URE_Editor, and its ‘object’/role-selection request parameters are constrained to known values.
  • Update: URE_Base_Lib::get_blog_ids() now uses get_sites() instead of a raw database query.
  • Update: URE_Capability::revoke_caps() now uses get_users() instead of a raw database query.
  • Update: URE_Protect_Admin::has_administrator_role() now uses user_can() instead of a raw database query.

[4.65] 21.05.2026

  • Update: Marked as compatible with WordPress 7.0
  • Update: Pages markup are modified to correspond WordPress 7.0 CSS changes.
  • Update: “defined(‘ABSPATH’)” guard was added to all PHP files to exclude PHP files direct execution.
  • Update: sanitize_text_field(), sanitize_key(), sanitize_url() functions are used to secure user input before processing.
  • Update: _nonce field checking was added before data update in addition to test made already on the higher level.

File changelog.txt contains the full list of changes.