CVE-2025-13540
BaseFortify
Publication date: 2025-11-27
Last updated on: 2025-11-27
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| wordpress | tiare_membership | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-269 | The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability in the Tiare Membership plugin for WordPress allows unauthenticated attackers to escalate their privileges by exploiting the 'tiare_membership_init_rest_api_register' function. This function does not restrict the user roles that can be registered, enabling attackers to register with the 'administrator' role and gain full administrator access to the site.
How can this vulnerability impact me? :
This vulnerability can have a severe impact as it allows attackers to gain administrator access to a WordPress site without authentication. With administrator privileges, attackers can control the site, modify content, steal data, install malicious software, or disrupt services, leading to significant security breaches.