CVE-2025-13851: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13851 is a privilege escalation vulnerability in the Buyent Classified plugin for WordPress (bundled with the Buyent theme), affecting all versions up to and including 1.0.7. The flaw allows unauthenticated attackers to register accounts with arbitrary roles — including administrator — by manipulating the _buyent_classified_user_type parameter via the REST API registration endpoint. It was published on February 19, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Red Hat CVE, Wordfence).

Technical details

The root cause is improper privilege management (CWE-269): the plugin's REST API registration endpoint does not validate or restrict the user role supplied by the client during account creation. An unauthenticated attacker can send a crafted POST request to the registration endpoint, setting the _buyent_classified_user_type parameter to administrator (or any other WordPress role), and the plugin will create the account with that role without any server-side authorization check. No authentication, special configuration, or user interaction is required to exploit this flaw (Red Hat CVE, Wordfence).

Impact

Successful exploitation grants an unauthenticated attacker full administrative control over the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker with administrator access can read all site data (including user credentials and private content), modify or delete content, install malicious plugins or themes, inject malware, and potentially pivot to the underlying server or connected systems. The vulnerability affects any WordPress installation running the Buyent theme with the bundled Buyent Classified plugin version 1.0.7 or earlier (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is approximately 0.055%, reflecting a currently low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the trivial exploitation conditions — no authentication, no user interaction, network-accessible REST API — make it a high-priority target if weaponized.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Buyent theme (and bundled Buyent Classified plugin ≤ 1.0.7) via web fingerprinting tools (e.g., WPScan, Shodan, or HTTP response headers/meta tags).
  2. Locate the REST API endpoint: Enumerate the WordPress REST API to find the Buyent Classified user registration endpoint (typically under /wp-json/ namespace used by the plugin).
  3. Craft the registration request: Send an unauthenticated HTTP POST request to the registration endpoint, including standard registration fields (username, email, password) and setting the _buyent_classified_user_type parameter to administrator.
  4. Verify account creation: Confirm that the newly created account has administrator privileges by logging into the WordPress dashboard (/wp-admin/) with the registered credentials.
  5. Achieve full site control: Use the administrator account to install a malicious plugin, create a web shell, exfiltrate data, or perform any other action available to a WordPress administrator (Red Hat CVE, Wordfence).

Indicators of compromise

  • Network: Unexpected POST requests to the WordPress REST API registration endpoint (e.g., /wp-json/<buyent-namespace>/register or similar) from unknown or external IP addresses, particularly with unusual role-related parameters.
  • Logs: WordPress access logs (access.log) showing REST API registration calls with _buyent_classified_user_type=administrator or other elevated role values; authentication logs showing new administrator logins from unfamiliar IPs.
  • WordPress Admin: Presence of unexpected administrator accounts in the WordPress user list (/wp-admin/users.php) with recent registration timestamps and no known association to legitimate users.
  • File System: Newly installed plugins or themes not authorized by site administrators; presence of web shells or PHP backdoors in the WordPress uploads or plugins directories.
  • Process/Behavior: Unusual outbound connections from the web server process; unexpected changes to WordPress core files or wp-config.php.

Mitigation and workarounds

No patched version of the Buyent Classified plugin beyond 1.0.7 has been confirmed as available at the time of disclosure. Site administrators should immediately deactivate and remove the Buyent Classified plugin from all affected WordPress installations until a patched version is released. As an interim measure, restrict access to WordPress REST API endpoints at the network or WAF level to trusted IP ranges where operationally feasible. Audit all WordPress user accounts for unauthorized administrator accounts and remove any that are not recognized. Monitor WordPress registration logs for suspicious activity (Red Hat CVE, Wordfence).

Community reactions

Wordfence included CVE-2025-13851 in their weekly WordPress vulnerability report for the period of February 16–22, 2026, highlighting it as a critical privilege escalation issue (Wordfence). The vulnerability was also noted on Mastodon by security community accounts shortly after disclosure. No significant vendor statement from the Buyent theme/plugin developer has been publicly identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management