9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can be exploited with the 'fs_type' parameter if the Flex Store Seller plugin is also activated.
AI Analysis
Unauthenticated Privilege Escalation vulnerability in Flex Store Users plugin for WordPress due to insufficient role restrictions during user registration.
Basic Information
ID
CVE-2025-13619
Source
Wordfence
Published
Dec 20, 2025 at 06:22
Affected Product
Vendor
CMSSuperHeroes
Product
Flex Store Users
Version
*
Affected Versions
CMSSuperHeroes Flex Store Users *
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
CMSSuperHeroes
Product
Flex Store Users
Version
1.1.0