CVE-2025-13618

CRITICAL

Mentoring <= 1.2.8 - Unauthenticated Privilege Escalation in mentoring_process_registration

Title source: cna
STIX 2.1

Description

The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_registration() function. This makes it possible for unauthenticated attackers to register with administrator-level user accounts.

Scores

CVSS v3 9.8
EPSS 0.0034
EPSS Percentile 25.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
dreamstechnologies/Mentoring < 1.2.8
Published May 05, 2026
Tracked Since May 05, 2026