CVE-2025-13851Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This makes it possible for unauthenticated attackers to register accounts with arbitrary roles, including administrator, by manipulating the _buyent_classified_user_type parameter during the registration process, granting them complete control over the WordPress site.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-19); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-19: 3Mentions · 2026-03-04: 1PoC Mentioned / Linked · 2026-02-19: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-02-19: 3Technical Details · 2026-03-04: 102-1903-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-193
Disclosure3
2026-03-041
Patch1
Full discourse4 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2025-13851: Critical #WordPress privilege escalation vulnerability https://nvd.nist.gov/vuln/detail/CVE-2025-13851 The Buyent Classified plugin (bundled with the Buyent theme) ≤ 1.0.7 fails to validate user roles during registration via its REST API. Attackers can manipulate the user parameters to create accounts with administrator privileges - gaining full control of the site. ⚠️ Why it matters: This flaw requires no authentication and carries a CVSS score of 9.8 (critical), meaning attackers can compromise confidentiality, integrity, and availability of affected sites. 🛠 Mitigation: Update or remove the vulnerable plugin/theme immediately and audit existing admin accounts for suspicious activity. #WordPressSecurity #CVE #WebSecurity #Malware #FullPerimeterProtection #SilentRisk #WordPress

    Post summary

    CVE-2025-13851 is a critical privilege‑escalation flaw in the Buyent Classified plugin that allows unauthenticated attackers to create administrator accounts via the REST API. Users should immediately update or remove the plugin/theme and audit existing admin accounts.

    0000078
    37 followersView on X
  • CVETodo@CveTodo
    Disclosure

    This flaw effectively enables attackers to escalate their privileges from unauthenticated users to full administrative control over the WordPress site, leading to severe security implications. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #PrivilegeEscalation https://cvetodo.com/cve/CVE-2025-13851

    Post summary

    The post announces a privilege‑escalation flaw in WordPress (CVE‑2025‑13851) describing its impact, but offers no PoC, exploit code, or mitigation details.

    0000028
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-13851 The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and includin… https://www.cve.org/CVERecord?id=CVE-2025-13851

    Post summary

    The Buyent Classified WordPress plugin is vulnerable to privilege escalation through user registration (CVE‑2025‑13851).

    00000165
    56.4K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-13851: Buyent Theme (with Buyent Classi... Trivial REST API parameter manipulation in Buyent Classified lets anyone register as admin - zero auth required, instan... https://zerodaysignal.com/vulnerability/CVE-2025-13851 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2025-13851, describing a trivial REST API parameter manipulation that lets anyone register as admin without authentication, and links to a vulnerability page for more details.

    0000051
    131 followersView on X

Explore more