PT-2025-48230 · WordPress · Tiger Theme

Ismail Syaleh

·

Published

2025-11-27

·

Updated

2025-11-28

·

CVE-2025-13675

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Tiger theme for WordPress versions prior to 101.2.2
Description The Tiger theme for WordPress is susceptible to a privilege escalation issue. The paypal-submit.php file does not properly restrict user roles during registration. This allows unauthenticated attackers to specify the 'administrator' role during registration, thereby gaining administrative access to the site.
Recommendations Versions prior to 101.2.2: Disable the paypal-submit.php file.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-13675

Affected Products

Tiger Theme