
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13563 is a privilege escalation vulnerability in the Lizza LMS Pro plugin for WordPress, affecting all versions up to and including 1.0.3. The flaw allows unauthenticated attackers to register as an administrator by supplying the 'administrator' role during the user registration process. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly).
The root cause is improper privilege management (CWE-269) in the lizza_lms_pro_register_user_front_end function, which fails to validate or restrict the user role supplied during front-end registration. An unauthenticated attacker can craft a registration request that includes the administrator role parameter, which the function accepts without restriction and assigns to the newly created account. No authentication, special configuration, or user interaction is required to exploit this vulnerability (Feedly, Wordfence).
Successful exploitation grants the attacker full administrative access to the WordPress site, enabling complete site compromise. This includes unauthorized access to sensitive user and site data, modification or deletion of content, installation of malicious plugins or themes, manipulation of existing user accounts, and potential distribution of malware through the compromised site. The impact spans confidentiality, integrity, and availability at the highest level (Feedly).
As of the time of reporting, no public proof-of-concept exploit code has been identified and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.055%, indicating a currently low probability of exploitation in the near term. The vulnerability has been detected by Qualys (detection ID 530973) and is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).
/wp-content/plugins/lizza-lms-pro/) using tools like Shodan, Censys, or Google dorks.administrator (e.g., role=administrator).lizza_lms_pro_register_user_front_end function processes the role without validation and creates the account with administrator privileges./wp-admin/) with full administrative control (Feedly).administrator role, especially accounts created via front-end registration rather than the admin dashboard; review wp_users and wp_usermeta tables for unexpected administrator-role entries.role parameter with the value administrator.wp-config.php or other core files.No patched version of the Lizza LMS Pro plugin has been confirmed as available. The recommended immediate action is to disable or remove the plugin from all WordPress installations running version 1.0.3 or earlier. As a temporary workaround, administrators should restrict access to the plugin's registration endpoint via a web application firewall (WAF) or server-level access controls, and audit all existing user accounts for unauthorized administrator entries. Monitor WordPress user creation logs closely for suspicious activity until an official patch is released (Feedly, Wordfence).
Wordfence included CVE-2025-13563 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as a notable privilege escalation issue (Wordfence). The vulnerability received brief attention on social media platforms including Mastodon, with security community members sharing awareness of the issue. No major vendor statements or in-depth researcher write-ups beyond initial disclosure have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."