CVE-2025-8572

CRITICAL

Truelysell Core <1.8.7 - Privilege Escalation

Title source: llm

Description

The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7. This is due to insufficient validation of the user_role parameter during user registration. This makes it possible for unauthenticated attackers to create accounts with elevated privileges, including administrator access.

Exploits (2)

github SUSPICIOUS 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2025/CVE-2025-8572
nomisec SUSPICIOUS 2 stars
by richardpaimu34 · poc
https://github.com/richardpaimu34/CVE-2025-8572

Scores

CVSS v3 9.8
EPSS 0.0003
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-269
Status published
Products (1)
dreamstechnologies/Truelysell Core < 1.8.7
Published Feb 14, 2026
Tracked Since Feb 18, 2026