The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 19 Feb 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Buddhathemes
Buddhathemes lizza Lms Pro Wordpress Wordpress wordpress |
|
| Vendors & Products |
Buddhathemes
Buddhathemes lizza Lms Pro Wordpress Wordpress wordpress |
Thu, 19 Feb 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. | |
| Title | Lizza LMS Pro <= 1.0.3 - Unauthenticated Privilege Escalation | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-19T04:36:20.596Z
Reserved: 2025-11-22T17:13:16.491Z
Link: CVE-2025-13563
No data.
Status : Awaiting Analysis
Published: 2026-02-19T07:17:30.870
Modified: 2026-02-19T15:53:02.850
Link: CVE-2025-13563
No data.
OpenCVE Enrichment
Updated: 2026-02-19T10:06:59Z
Weaknesses