PT-2026-23828 · WordPress · Paid Videochat Turnkey Site – Html5 Ppv Live Webcams
Peter Thaleikis
·
Published
2026-03-07
·
Updated
2026-03-12
·
CVE-2025-8899
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress versions through 7.3.20
Description
The Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress is susceptible to a privilege escalation issue. The
videowhisper register form() function does not adequately restrict user roles during registration. This allows authenticated attackers with Author-level access or higher to create posts or pages containing a registration form configured to assign administrator privileges. Attackers can then utilize this form to register a new administrator account, effectively gaining administrative control. While contributors can also attempt this exploit, its success depends on an administrator approving the form with the administrator role assigned.Recommendations
Update the Paid Videochat Turnkey Site – HTML5 PPV Live Webcams plugin for WordPress to version 7.3.21.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paid Videochat Turnkey Site – Html5 Ppv Live Webcams