Description
The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.
Problem types
CWE-269 Improper Privilege Management
Product status
* (semver)
Timeline
| 2025-07-22: | Discovered |
| 2025-11-17: | Vendor Notified |
| 2026-02-13: | Disclosed |
Credits
Alyudin Nafiie
References
www.wordfence.com/...-3144-4783-b646-ee1e02cd27ef?source=cve
themeforest.net/...-service-booking-wordpress-theme/43398124