CVE-2025-12882Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to gain elevated privileges by registering an account with the administrator role.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-19: 2PoC Mentioned / Linked · 2026-02-19: 1Technical Details · 2026-02-19: 202-19
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVETodo@CveTodo
    Disclosure

    CVE-2025-12882 pertains to a privilege escalation flaw in the **Clasifico Listing plugin for WordPress** (up to version 2.0). The core issue stems from the plugin allowing users who register new accounts to specify their user role via the `listing_user_role` parameter. Since this parameter is not properly validated or restricted, unauthenticated attackers can exploit it to assign themselves elevated privileges, including the **administrator** role. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-12882

    Post summary

    The post discloses a privilege escalation flaw in the Clasifico Listing WordPress plugin, where unauthenticated users can elevate privileges via an unvalidated parameter; no proof of concept, exploit, patch, or active exploitation information is provided.

    0000036
    20 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-12882: Clasifico Listing <= 2.0 - Unaut... Classic parameter injection in Clasifico Listing lets attackers set arbitrary user_role during registration - instant a... https://zerodaysignal.com/vulnerability/CVE-2025-12882 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A parameter injection flaw in Clasifico Listing <=2.0 (CVE‑2025‑12882) allows attackers to set arbitrary user roles during registration, with a PoC available via the linked ZeroDaySignal page. No evidence of active exploitation, patches, or debunking is provided.

    0000047
    131 followersView on X

Explore more