
CVE-2025-12882 pertains to a privilege escalation flaw in the **Clasifico Listing plugin for WordPress** (up to version 2.0). The core issue stems from the plugin allowing users who register new accounts to specify their user role via the `listing_user_role` parameter. Since this parameter is not properly validated or restricted, unauthenticated attackers can exploit it to assign themselves elevated privileges, including the **administrator** role. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-12882
Post summary
The post discloses a privilege escalation flaw in the Clasifico Listing WordPress plugin, where unauthenticated users can elevate privileges via an unvalidated parameter; no proof of concept, exploit, patch, or active exploitation information is provided.

