Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 28 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elated Themes
Elated Themes findall Listing Wordpress Wordpress wordpress |
|
| Vendors & Products |
Elated Themes
Elated Themes findall Listing Wordpress Wordpress wordpress |
Thu, 27 Nov 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can only be exploited if the FindAll Membership plugin is also activated, because user registration is in that plugin. | |
| Title | FindAll Listing <= 1.0.5 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:36:49.908Z
Reserved: 2025-11-22T04:52:29.052Z
Link: CVE-2025-13538
Updated: 2025-11-28T14:42:09.888Z
Status : Deferred
Published: 2025-11-27T05:16:12.453
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-13538
No data.
OpenCVE Enrichment
Updated: 2026-04-22T16:45:21Z