
**CVE-2025-13563** pertains to a privilege escalation flaw within the **Lizza LMS Pro** plugin for WordPress, affecting all versions up to and including **1.0.3**. The core issue arises from the `lizza_lms_pro_register_user_front_end` function, which fails to restrict user roles during registration. This oversight allows unauthenticated attackers to specify the `administrator` role when registering a new user, thereby gaining administrative privileges on the affected WordPress site. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-13563
Post summary
The post announces a privilege‑escalation vulnerability in the Lizza LMS Pro WordPress plugin, detailing how attackers can register as administrators without authentication.


