Impact
The Lizza LMS Pro plugin includes an insecure user registration function that accepts any role value. An attacker can submit the role "administrator" even without being logged in, thereby creating a new administrator account. This grants the attacker full control over the WordPress site, including the ability to install plugins, modify content, access sensitive data, and compromise other user accounts.
Affected Systems
The vulnerability affects BuddhaThemes' Lizza LMS Pro plugin for WordPress in all releases up to and including version 1.0.3. Any site deploying these versions without additional restrictions is at risk.
Risk and Exploitability
The CVSS base score is 9.8, indicating critical severity, while the EPSS score is less than 1 %, showing a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely attack vectors involve submitting crafted registration requests through the front‑end registration endpoint, which is publicly accessible, allowing unauthenticated users to trigger the privilege escalation.
OpenCVE Enrichment