PT-2025-48227 · WordPress · Findall Membership+1

Ismail Syaleh

·

Publicado

2025-11-27

·

Atualizado

2026-04-08

·

CVE-2025-13538

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FindAll Listing versions prior to 1.0.6
Description The FindAll Listing plugin for WordPress is susceptible to a privilege escalation issue. This occurs because the findall listing user registration additional params function does not properly limit the user roles that can be selected during registration. This allows unauthenticated attackers to assign themselves the 'administrator' role during the registration process, thereby gaining administrative access to the WordPress site. This exploitation is only possible if the FindAll Membership plugin is also active, as it handles the user registration process.
Recommendations Versions prior to 1.0.6 should be updated. As a temporary measure, disable user registration functionality.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-13538

Produtos afetados

Findall Listing
Findall Membership