CVE-2025-12981 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: February 27, 2026
Listee WordPress theme - Privilege Escalation
Published: February 27, 2026Updated: February 27, 2026Remote Exploitable
Overview
Listee WordPress theme <= 1.1.6 contains a privilege escalation caused by improper sanitization of the user_role parameter in the bundled listee-core plugin's user registration function, letting unauthenticated attackers register as Administrator, exploit requires unauthenticated user registration.
Severity & Score
Severity: Critical
CVSS Score: 9.8
Impact
Unauthenticated attackers can register as Administrator, gaining full control over the WordPress site.
Mitigation
Update to a version later than 1.1.6 or the latest available version.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d534feae-d1b7-4544-b1c5-c23f37dd5bab?source=cve
- https://listee-wp.dreamstechnologies.com/documentation/changelog.html
- https://themeforest.net/item/listee-classified-ads-wordpress-theme/44526956
- https://themes.trac.wordpress.org/browser/listee/1.1.5/listee-core/includes/listee-core-users.php#L928
Related Resources
Details
- CVE ID
- CVE-2025-12981
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- broken_access_control
- Status
- new
CWE
- CWE-269
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H