CVE-2025-13618Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_registration() function. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-05-05); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-05-05: 3Mentions · 2026-05-16: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-16: 1Technical Details · 2026-05-05: 2Technical Details · 2026-05-16: 105-0505-16
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-053
Disclosure2Patch1
2026-05-161
Patch1
Full discourse4 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2025-13618 — CVSS 9.8/10 ██████████ The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8.... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/KOrs8gyGhF

    Post summary

    Mentoring plugin for WordPress has a critical privilege‑escalation vulnerability (CVE-2025-13618, CVSS 9.8) affecting all versions up to 1.2.8; users are urged to apply the immediate patch.

    10000996
    26 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    A new high-severity vulnerability (CVE-2025-13618) affects the WordPress Mentoring plugin, allowing attackers to gain admin-level access. Update to version 1.2.9 or later immediately to protect your site. ADK Cyber can help secure your digital assets. #Cybersecurity

    Post summary

    CVE-2025-13618 is a high‑severity flaw in the WordPress Mentoring plugin that lets attackers obtain admin access; updating to version 1.2.9 or newer is the recommended mitigations.

    000001.5K
    80 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-13618 Privilege Escalation in WordPress Mentoring Plugin Versions Up to 1.2.8 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-13618

    Post summary

    The brief notice announces a privilege‑escalation vulnerability in WordPress Mentoring Plugin up to version 1.2.8, without mentioning PoC, exploitation, or patches.

    00000577
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2025-13618 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2025-13618 #CVE-2025-13618 #CVE #Critical #Wordpress #CyberSecurity #InfoSec https://t.co/l2QPQqdmgL

    Post summary

    The tweet announces the CVE-2025-13618 vulnerability for WordPress with a critical severity score of 9.8 and links to the NVD for further details.

    00000964
    151 followersView on X

Explore more