Impact
The Buyent Classified plugin for WordPress, bundled with the Buyent theme, permits an attacker to create user accounts with arbitrary roles through the REST API because the _buyent_classified_user_type parameter is not validated. An unauthenticated attacker can register an account as administrator, giving full control over the WordPress site. This flaw is a privilege escalation vulnerability (CWE‑269) that can lead to comprehensive compromise of the site, including content management, plugin installation, and access to sensitive data.
Affected Systems
The issue impacts the Buyent Classified plugin for WordPress bundled with the Buyent theme in all releases up to and including version 1.0.7. Any WordPress installation that contains these versions of the plugin and theme is affected.
Risk and Exploitability
The CVSS score of 9.8 signals a critical level of severity. The EPSS score of less than 1% indicates a low current exploitation probability, yet the flaw is remote and unauthenticated, presenting a high risk to attackers. Although not listed in the CISA KEV catalog, the potential impact necessitates urgent remediation. An attacker can exploit the flaw by sending a crafted REST API request to the registration endpoint with a selected _buyent_classified_user_type value, bypassing role restrictions.
OpenCVE Enrichment