The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
History

Mon, 10 Mar 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 08 Mar 2025 08:30:00 +0000

Type Values Removed Values Added
Description The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Title Javo Core <= 3.0.0.080 - Unauthenticated Privilege Escalation in ajax_signup
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-03-08T08:22:57.176Z

Updated: 2025-03-10T15:55:37.070Z

Reserved: 2025-01-02T18:41:56.474Z

Link: CVE-2025-0177

cve-icon Vulnrichment

Updated: 2025-03-10T15:55:33.712Z

cve-icon NVD

Status : Received

Published: 2025-03-08T09:15:31.420

Modified: 2025-03-08T09:15:31.420

Link: CVE-2025-0177

cve-icon Redhat

No data.