PT-2025-8917 · WordPress · Buddypress+1

Tonn

·

Published

2025-02-27

·

Updated

2025-02-27

·

CVE-2025-1295

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Templines Elementor Helper Core plugin for WordPress versions up to and including 2.7
Description The issue allows for privilege escalation due to the ability to perform arbitrary user meta updates. This enables authenticated attackers with Subscriber-level access or higher to elevate their role to Administrator. The exploitation of this issue is contingent upon the presence and activation of the BuddyPress plugin.
Recommendations For Templines Elementor Helper Core plugin for WordPress versions up to and including 2.7, consider disabling the plugin until a patch is available to prevent exploitation. Restrict access to user meta updates to minimize the risk of privilege escalation.

Fix

LPE

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2025-1295

Affected Products

Buddypress
Templines Elementor Helper Core