CVE-2025-13563: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13563 is a privilege escalation vulnerability in the Lizza LMS Pro plugin for WordPress, affecting all versions up to and including 1.0.3. The flaw allows unauthenticated attackers to register as an administrator by supplying the 'administrator' role during the user registration process. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly).

Technical details

The root cause is improper privilege management (CWE-269) in the lizza_lms_pro_register_user_front_end function, which fails to validate or restrict the user role supplied during front-end registration. An unauthenticated attacker can craft a registration request that includes the administrator role parameter, which the function accepts without restriction and assigns to the newly created account. No authentication, special configuration, or user interaction is required to exploit this vulnerability (Feedly, Wordfence).

Impact

Successful exploitation grants the attacker full administrative access to the WordPress site, enabling complete site compromise. This includes unauthorized access to sensitive user and site data, modification or deletion of content, installation of malicious plugins or themes, manipulation of existing user accounts, and potential distribution of malware through the compromised site. The impact spans confidentiality, integrity, and availability at the highest level (Feedly).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been identified and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.055%, indicating a currently low probability of exploitation in the near term. The vulnerability has been detected by Qualys (detection ID 530973) and is not listed in the CISA Known Exploited Vulnerabilities catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Lizza LMS Pro plugin (versions ≤ 1.0.3) by searching for plugin-specific indicators (e.g., /wp-content/plugins/lizza-lms-pro/) using tools like Shodan, Censys, or Google dorks.
  2. Locate registration endpoint: Navigate to the front-end user registration form provided by the plugin, typically accessible without authentication.
  3. Craft malicious registration request: Intercept the registration form submission using a proxy tool (e.g., Burp Suite) and modify the request to include a role parameter set to administrator (e.g., role=administrator).
  4. Submit the request: Send the crafted POST request to the registration endpoint. The lizza_lms_pro_register_user_front_end function processes the role without validation and creates the account with administrator privileges.
  5. Authenticate as administrator: Log in to the WordPress site using the newly registered credentials and access the WordPress admin dashboard (/wp-admin/) with full administrative control (Feedly).

Indicators of compromise

  • Logs: WordPress authentication logs showing newly registered accounts with the administrator role, especially accounts created via front-end registration rather than the admin dashboard; review wp_users and wp_usermeta tables for unexpected administrator-role entries.
  • Network: Unusual POST requests to the Lizza LMS Pro registration endpoint containing a role parameter with the value administrator.
  • File System: Presence of newly installed or modified plugins/themes following unexpected administrator account creation; changes to wp-config.php or other core files.
  • Process/Behavior: New administrator accounts appearing in the WordPress user list without corresponding admin-initiated creation; unexpected plugin installations or site setting changes logged in the WordPress activity log (Feedly).

Mitigation and workarounds

No patched version of the Lizza LMS Pro plugin has been confirmed as available. The recommended immediate action is to disable or remove the plugin from all WordPress installations running version 1.0.3 or earlier. As a temporary workaround, administrators should restrict access to the plugin's registration endpoint via a web application firewall (WAF) or server-level access controls, and audit all existing user accounts for unauthorized administrator entries. Monitor WordPress user creation logs closely for suspicious activity until an official patch is released (Feedly, Wordfence).

Community reactions

Wordfence included CVE-2025-13563 in its weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as a notable privilege escalation issue (Wordfence). The vulnerability received brief attention on social media platforms including Mastodon, with security community members sharing awareness of the issue. No major vendor statements or in-depth researcher write-ups beyond initial disclosure have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management