PT-2025-50569 · WordPress · Wp Cardealer

Friderika Baranyai

·

Published

2025-12-11

·

Updated

2025-12-11

·

CVE-2025-13764

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WP CarDealer plugin for WordPress versions prior to 1.2.17
Description The WP CarDealer plugin for WordPress is susceptible to a privilege escalation issue. The WP CarDealer User::process register function does not adequately restrict user role assignments during registration. This allows unauthenticated attackers to register with the 'administrator' role, gaining unauthorized administrative access to the WordPress site.
Recommendations Versions prior to 1.2.17 should be updated. As a temporary workaround, restrict user registrations until a patch is available.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-13764

Affected Products

Wp Cardealer