PT-2025-46244 · WordPress · Mementor Core

Youcef Hamdani

·

Published

2025-11-11

·

Updated

2025-11-16

·

CVE-2025-11168

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mementor Core plugin for WordPress versions up to and including 2.2.5
Description The plugin does not properly handle the user switch back function, allowing authenticated attackers with Subscriber-level access or above to elevate their privileges and access an administrator account through the switch back functionality. This results in a privilege escalation flaw where users can impersonate an administrator.
Recommendations Update Mementor Core plugin to a version later than 2.2.5.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-11168

Affected Products

Mementor Core