CVE-2025-12981Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properly sanitize the user_role parameter. This makes it possible for unauthenticated attackers to register as Administrator by manipulating the user_role parameter during registration.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 5 mentions (2026-02-27); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01345Mentions · 2026-02-27: 5Mentions · 2026-03-04: 1Mentions · 2026-03-17: 1Mentions · 2026-03-19: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-02-27: 4Technical Details · 2026-03-04: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-19: 102-2703-0403-1703-19
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-275
Disclosure4General1
2026-03-041
Disclosure1
2026-03-171
Patch1
2026-03-191
Disclosure1
Full discourse8 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    CVE-2025-12981 (CVSS 9.8) A WordPress theme flaw lets attackers register as Admin — no login required. https://nvd.nist.gov/vuln/detail/CVE-2025-12981 ⚠️ Why it matters: • Full site takeover • Malware/plugin injection • Payment skimmers & SEO spam • Complete loss of store control Root cause? Broken validation → user_role manipulation during registration. 🔍 How to defend: • Audit new admin accounts immediately • Monitor user registration activity • Enforce strict role validation • Scan for hidden malware & unauthorized changes Attackers don’t hack in… they register in. Protect your full perimeter: https://quttera.com/wordpress-malware-scanner #WordPress #WooCommerce #CVE #CyberSecurity #FullPerimeterProtection #SilentRisk

    Post summary

    A newly disclosed WordPress theme vulnerability (CVE‑2025‑12981) allows attackers to register as an admin without login, posing a risk of full site takeover; the post offers defensive steps but does not provide PoC, exploit code, or patch information.

    00000154
    37 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CRITICAL VULNERABILITY ALERT CVE-2025-12981 (CVSS: 9.8) A severe privilege escalation flaw has been found in the "Listee" theme for WordPress (versions <= 1.1.6). Due to poor validation in the listee-core plugin, unauthenticated attackers can manipulate the user_role parameter during registration to instantly grant themselves full Administrator access! 🛠️👾 If you are using the Listee theme, check for updates, patch immediately, or disable the theme to prevent a complete site takeover. #CyberSecurity #WordPress #CVE #InfoSec #Vulnerability #CVE_2025_12981

    Post summary

    Critical privilege escalation bug in Listee WordPress theme (CVE-2025-12981) warns attackers can gain admin via user_role manipulation; users urged to update or disable the theme immediately.

    00000113
    37 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2025-12981 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i..https://nvd.nist.gov/vuln/detail/CVE-2025-12981 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE-2025-12981 is a critical privilege escalation vulnerability affecting the Listee WordPress theme up to version 1.1.6, with no PoC, exploit, or patch details provided.

    0000042
    173 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-12981 Unauthenticated Administrator Privilege Escalation in Listee WordPress Theme https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-12981

    Post summary

    The content merely cites CVE-2025-12981 as an unauthenticated administrator privilege escalation in the Listee WordPress Theme, with a link to a vulnerability detail page, but provides no further technical, exploit, or mitigation information.

    0000070
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-12981 The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bund… https://www.cve.org/CVERecord?id=CVE-2025-12981

    Post summary

    The text announces a privilege escalation flaw in the Listee WordPress theme (CVE‑2025‑12981) caused by a broken validation check, but provides no PoC, exploit, or mitigation details.

    0000096
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2025-12981: CRITICAL] WordPress Listee theme versions up to 1.1.6 have a security flaw allowing unauthenticated users to escalate privileges to Administrator. A fix is needed for this user registration ...#cve,CVE-2025-12981,#cybersecurity https://cvefind.com/CVE-2025-12981

    Post summary

    A critical privilege‑escalation flaw in WordPress Listee theme versions up to 1.1.6 allows unauthenticated users to gain Administrator rights, necessitating a patch.

    0000052
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-12981** pertains to a critical privilege escalation vulnerability in the **Listee** theme for WordPress, specifically affecting all versions up to and including **1.1.6**. The core issue resides within the **listee-core plugin's user registration function**, which fails to properly sanitize the **user_role** parameter during registration. This flaw enables **unauthenticated attackers** to manipulate the registration process, allowing them to register as **Administrators**. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-12981

    Post summary

    The CVE-2025-12981 vulnerability allows unauthenticated attackers to register as administrators in the Listee WordPress theme due to improper sanitization of the user_role parameter.

    0000052
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-12981 - Critical The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugi... https://www.thehackerwire.com/vulnerability/CVE-2025-12981/ https://t.co/9BvaKt5cK7

    Post summary

    CVE‑2025‑12981 is a critical privilege‑escalation flaw in the Listee WordPress theme up to version 1.1.6, caused by a broken validation check in the bundled listee‑core plugin.

    0000060
    119 followersView on X

Explore more