PT-2025-50569 · WordPress · Wp Cardealer

·

CVE-2025-13764

·

Published

2025-12-11

·

Updated

2025-12-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP CarDealer plugin for WordPress versions prior to 1.2.17
Description The WP CarDealer plugin for WordPress is susceptible to a privilege escalation issue. The WP CarDealer User::process register function does not adequately restrict user role assignments during registration. This allows unauthenticated attackers to register with the 'administrator' role, gaining unauthorized administrative access to the WordPress site.
Recommendations Versions prior to 1.2.17 should be updated. As a temporary workaround, restrict user registrations until a patch is available.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13764

Affected Products

Wp Cardealer