PT-2025-48231 · WordPress · Wordpress Tiger Theme
István Márton
·
Published
2025-11-27
·
Updated
2025-11-27
·
CVE-2025-13680
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WordPress Tiger theme versions prior to 101.2.2
Description
The Tiger theme for WordPress allows privilege escalation due to a flaw in the
set role() function. Authenticated attackers with Subscriber-level access or higher can elevate their privileges to administrator level. The vulnerable component is the $user->set role() function, which allows modification of a user's role.Recommendations
Update the WordPress Tiger theme to version 101.2.2 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Tiger Theme