CVE-2025-13563Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-19: 3Technical Details · 2026-02-19: 202-19
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVETodo@CveTodo
    Disclosure

    **CVE-2025-13563** pertains to a privilege escalation flaw within the **Lizza LMS Pro** plugin for WordPress, affecting all versions up to and including **1.0.3**. The core issue arises from the `lizza_lms_pro_register_user_front_end` function, which fails to restrict user roles during registration. This oversight allows unauthenticated attackers to specify the `administrator` role when registering a new user, thereby gaining administrative privileges on the affected WordPress site. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-13563

    Post summary

    The post announces a privilege‑escalation vulnerability in the Lizza LMS Pro WordPress plugin, detailing how attackers can register as administrators without authentication.

    0000034
    20 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-13563 The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_u… https://www.cve.org/CVERecord?id=CVE-2025-13563

    Post summary

    The statement notes a privilege escalation vulnerability in the Lizza LMS Pro WordPress plugin but provides no supporting proof, exploit details, or mitigation guidance.

    00000118
    56.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-13563: Lizza LMS Pro <= 1.0.3 - Unauthe... Zero-effort admin takeover in Lizza LMS Pro via role parameter manipulation during registration - no auth required, pur... https://zerodaysignal.com/vulnerability/CVE-2025-13563 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2025-13563, detailing a zero-effort admin takeover in Lizza LMS Pro through role parameter manipulation during registration with no authentication required.

    0000059
    131 followersView on X

Explore more