CVE 9.8 CRITICAL

Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration_CVE-2025-8572

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.

AI Analysis

Unauthenticated privilege escalation vulnerability due to insufficient validation of the user_role parameter during user registration

Basic Information

ID CVE-2025-8572
Source Wordfence
Published Feb 14, 2026 at 08:26

Affected Product

Vendor dreamstechnologies
Product Truelysell Core
Version *
Affected Versions dreamstechnologies Truelysell Core *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor dreamstechnologies
Product Truelysell Core
Version <= 1.8.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.