CVE-2025-8572CRITICAL 9.8EPSS p34.9%

CVE-2025-8572CVE-2025-8572

Description

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.44% probability of exploitation · percentile 34.9% · 2026-06-18T12:00:27Z
Published2026-02-14
Last modified2026-04-15

Underlying weaknesses· 1

CWE-269

References

  1. https://themeforest.net/item/truelysell-service-booking-wordpress-theme/43398124
  2. https://www.wordfence.com/threat-intel/vulnerabilities/id/b027c9f9-3144-4783-b646-ee1e02cd27ef?source=cve

1

TypeTargetConfidenceTier
WeaknessImproper Privilege Managementcwe-2690%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-10742
CVE
CVE-2025-12882
CVE
CVE-2025-13764
CVE
CVE-2025-12981
CVE
CVE-2025-13851
CVE
CVE-2025-2563
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.