Skip to content

Menu
  • Home
Menu

CVE-2025-13851 – Buyent Theme (with Buyent Classified Plugin) <= 1.0.7 – Unauthenticated Privilege Escalation via User Registration

Posted on February 19, 2026
CVE ID : CVE-2025-13851

Published : Feb. 19, 2026, 4:36 a.m. | 3 hours, 26 minutes ago

Description : The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This makes it possible for unauthenticated attackers to register accounts with arbitrary roles, including administrator, by manipulating the _buyent_classified_user_type parameter during the registration process, granting them complete control over the WordPress site.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

Post Views: 10

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme