CVE-2025-13619CRITICAL 9.8EPSS p23.3%

CVE-2025-13619CVE-2025-13619

Description

The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site. Note: The vulnerability can be exploited with the 'fs_type' parameter if the Flex Store Seller plugin is also activated.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.32% probability of exploitation · percentile 23.3% · 2026-06-18T12:00:27Z
Published2025-12-20
Last modified2026-04-15

Underlying weaknesses· 1

CWE-269

References

  1. https://themeforest.net/item/autosmart-automotive-car-dealer-wordpress-theme/20322930
  2. https://www.wordfence.com/threat-intel/vulnerabilities/id/a2fc40ed-a6af-4069-be63-cb75e98cc98a?source=cve

1

TypeTargetConfidenceTier
WeaknessImproper Privilege Managementcwe-2690%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-13538
CVE
CVE-2025-13764
CVE
CVE-2025-11533
CVE
CVE-2025-14533
CVE
CVE-2025-14736
CVE
CVE-2025-12158
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.