nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-11533 CVE-2025-11533
CRITICAL
WP Freeio <= 1.2.21 - Unauthenticated Privilege Escalation
Record summary
CVE-2025-11533 has a selected CVSS score of 9.8 (critical).
Description
The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Oct 11, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 14, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WP FreeioBrowse ApusTheme / WP FreeioDefault status: unaffected | CVE List | Through 1.2.21 | affected |
WP Freeio plugin for WordPressBrowse ApusTheme / WP Freeio plugin for WordPress | VulnCheck | Version data not supplied | |
References
3themeforest.net
https://themeforest.net/item/freeio-freelance-marketplace-wordpress-theme/42045416 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/0db85f84-04e9-42eb-a16b-96554fbfd186?source=cve