CVE-2025-13851
The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This makes it possible for unauthenticated attackers to register accounts with arbitrary roles, including administrator, by manipulating the _buyent_classified_user_type parameter during the registration process, granting them complete control over the WordPress site.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.31%
- CWE
- CWE-269
- Published
- 2026-02-19
- Last modified
- 2026-03-13
Affected products
- scriptsbundle Buyent
Weakness type
Related vulnerabilities
- CVE-2026-75777 — Multiple vulnerabilities in IBM Aspera Enterprise Webapps
- CVE-2026-87958 — IBM® Db2® is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions
- CVE-2026-9327 — IBM WebSphere Application Server prior to 9.0.5.29 and 8.5.5.31 are affected by multiple vulnerabilities
- CVE-2026-88891 — OpenPanel Read-Only Access Level Enforcement Bypass via Mutations
- CVE-2026-88863 — capgo.app through 12.207.1 Privilege Escalation via invite_new_user_to_org
- CVE-2026-84042 — Crun: crun: rootful krun with passt executes container payload as host root
- CVE-2026-87998 — Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
- CVE-2026-86746 — Snipe-IT before 8.7.0 Authorization Bypass via Livewire Snapshot Replay