The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 14 Feb 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access. | |
| Title | Truelysell Core <= 1.8.7 - Unauthenticated Privilege Escalation via Registration | |
| Weaknesses | CWE-269 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-02-14T08:26:47.464Z
Reserved: 2025-08-04T22:01:31.166Z
Link: CVE-2025-8572
No data.
Status : Received
Published: 2026-02-14T09:16:11.490
Modified: 2026-02-14T09:16:11.490
Link: CVE-2025-8572
No data.
OpenCVE Enrichment
No data.
Weaknesses