CVE-2025-12882
Plain English Summary
AI-powered analysis for quick understanding
This vulnerability allows attackers to gain administrator privileges on a WordPress site simply by creating a new user account and choosing their own role. It affects versions of the Clasifico Listing plugin up to 2.0 and can be exploited by anyone, even those who are not logged in.
Technical Description
The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listing_user_role' parameter. This makes it possible for unauthenticated attackers to gain elevated privileges by registering an account with the administrator role.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Feb 19, 2026
about 2 months ago
Last Modified
Feb 19, 2026
about 2 months ago