PT-2025-10426 · WordPress · Javo Core

Tonn

·

Published

2025-03-08

·

Updated

2025-03-13

·

CVE-2025-0177

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Javo Core versions up to, and including, 3.0.0.080
Description The Javo Core plugin for WordPress is vulnerable to privilege escalation due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Recommendations For versions up to, and including, 3.0.0.080, update to a version later than 3.0.0.080 to resolve the issue. As a temporary workaround, consider disabling the account registration feature or restricting the role assignment capability to prevent unauthenticated attackers from gaining elevated privileges.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0177

Affected Products

Javo Core