PT-2026-8095 · WordPress · Truelysell Core

Alyudin Nafiie

·

Publicado

2026-02-14

·

Atualizado

2026-02-15

·

CVE-2025-8572

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Truelysell Core plugin for WordPress versions prior to 1.8.7
Description The Truelysell Core plugin for WordPress is subject to a privilege escalation issue. Insufficient validation of the user role parameter during user registration allows unauthenticated attackers to create accounts with elevated privileges, potentially including administrator access.
Recommendations Update the Truelysell Core plugin to a version greater than 1.8.7.

Correção

LPE

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-8572

Produtos afetados

Truelysell Core