CVE-2025-13675
Published: 27 November 2025
Description
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible for…
more
unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Mitigating Controls (NIST 800-53 r5)AI
AC-2 requires management of account creation and privilege assignment processes, directly preventing improper role specification like 'administrator' during unauthenticated registration in the paypal-submit.php file.
SI-10 mandates validation of information inputs such as the user role parameter, blocking arbitrary privilege escalation by rejecting unauthorized 'administrator' roles in the registration script.
AC-6 enforces least privilege by restricting accounts to only necessary permissions, mitigating the impact of any successful improper admin role assignment during registration.
Security SummaryAI
CVE-2025-13675 is a privilege escalation vulnerability in the Tiger theme for WordPress, affecting all versions up to and including 101.2.1. The flaw arises in the 'paypal-submit.php' file, which does not enforce restrictions on the user roles that can be assigned during registration, allowing arbitrary role specification. It is classified under CWE-269 (Improper Privilege Management) and carries a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting its critical severity.
Unauthenticated attackers can exploit this vulnerability over the network with low complexity and no user interaction required. By supplying the 'administrator' role during the registration process, they can gain full administrator access to the affected WordPress site, enabling complete control over content, users, plugins, and themes.
Advisories and additional details are provided by Wordfence in their threat intelligence report and on the Tiger theme's product page at ThemeForest. Security practitioners should consult these sources for patch availability or workaround recommendations, published as of 2025-11-27.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Unauthenticated remote exploitation of a public-facing WordPress application vulnerability (T1190) enables privilege escalation to administrator role (T1068).