
CVE-2025-13851: Critical #WordPress privilege escalation vulnerability https://nvd.nist.gov/vuln/detail/CVE-2025-13851 The Buyent Classified plugin (bundled with the Buyent theme) ≤ 1.0.7 fails to validate user roles during registration via its REST API. Attackers can manipulate the user parameters to create accounts with administrator privileges - gaining full control of the site. ⚠️ Why it matters: This flaw requires no authentication and carries a CVSS score of 9.8 (critical), meaning attackers can compromise confidentiality, integrity, and availability of affected sites. 🛠 Mitigation: Update or remove the vulnerable plugin/theme immediately and audit existing admin accounts for suspicious activity. #WordPressSecurity #CVE #WebSecurity #Malware #FullPerimeterProtection #SilentRisk #WordPress
Post summary
CVE-2025-13851 is a critical privilege‑escalation flaw in the Buyent Classified plugin that allows unauthenticated attackers to create administrator accounts via the REST API. Users should immediately update or remove the plugin/theme and audit existing admin accounts.



