Impact
The vulnerability arises because the Tiger theme’s paypal-submit.php script does not validate the role assigned during user registration. An attacker can submit a registration form with the administrator role before any authentication is required, resulting in immediate administrative privileges on the WordPress site. The impact is full control over site content, settings, and data, leading to potential data theft, site defacement, or further compromise.
Affected Systems
All versions of the Tiger theme for WordPress from the initial release up through and including 101.2.1 are affected. The theme is distributed via the WordPress theme marketplace and can be installed on any WordPress installation that supports the theme. No specific WordPress core versions are mentioned, so any site running these theme versions is at risk.
Risk and Exploitability
The CVSS score of 9.8 categorizes this as Critical, with the EPSS score indicating low current exploitation probability but not zero. Because the flaw allows unauthenticated privilege escalation through a publicly reachable form, the attack vector is a remote, unauthenticated web request. The vulnerability is not yet listed in the CISA KEV catalog, but its high severity warrants prompt remediation. Attackers could exploit this with minimal skill by submitting a crafted registration request directed at the paypal-submit.php endpoint.
OpenCVE Enrichment