PT-2025-48227 · WordPress · Findall Membership+1

Ismail Syaleh

·

Published

2025-11-27

·

Updated

2026-04-08

·

CVE-2025-13538

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FindAll Listing versions prior to 1.0.6
Description The FindAll Listing plugin for WordPress is susceptible to a privilege escalation issue. This occurs because the findall listing user registration additional params function does not properly limit the user roles that can be selected during registration. This allows unauthenticated attackers to assign themselves the 'administrator' role during the registration process, thereby gaining administrative access to the WordPress site. This exploitation is only possible if the FindAll Membership plugin is also active, as it handles the user registration process.
Recommendations Versions prior to 1.0.6 should be updated. As a temporary measure, disable user registration functionality.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-13538

Affected Products

Findall Listing
Findall Membership