PT-2026-23828 · WordPress · Paid Videochat Turnkey Site – Html5 Ppv Live Webcams

Peter Thaleikis

·

Publicado

2026-03-07

·

Atualizado

2026-03-12

·

CVE-2025-8899

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress versions through 7.3.20
Description The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is susceptible to a privilege escalation issue. The videowhisper register form() function does not adequately restrict user roles during registration. This allows authenticated attackers with Author-level access or higher to create posts or pages containing a registration form configured to assign administrator privileges. Attackers can then utilize this form to register a new administrator account, effectively gaining administrative control. While contributors can also attempt this exploit, its success depends on an administrator approving the form with the administrator role assigned.
Recommendations Update the Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress to version 7.3.21.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8899

Produtos afetados

Paid Videochat Turnkey Site – Html5 Ppv Live Webcams