CVE 9.8 CRITICAL

Buyent Theme (with Buyent Classified Plugin) <= 1.0.7 - Unauthenticated Privilege Escalation via User Registration_CVE-2025-13851

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the user role during registration via the REST API endpoint. This makes it possible for unauthenticated attackers to register accounts with arbitrary roles, including administrator, by manipulating the _buyent_classified_user_type parameter during the registration process, granting them complete control over the WordPress site.

AI Analysis

Unauthenticated privilege escalation via user registration due to missing validation of user roles

Basic Information

ID CVE-2025-13851
Source Wordfence
Published Feb 19, 2026 at 04:36

Affected Product

Vendor scriptsbundle
Product Buyent
Version *
Affected Versions scriptsbundle Buyent *

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Scriptsbundle
Product Buyent Classified Plugin
Version 1.0.7

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.