CVE-2025-1295
CVE-2025-1295
Título es
CVE-2025-1295
Jue, 27/02/2025 – 06:15
Tipo
CWE-269
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2025-1295
Descripción en
The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update their role to Administrator. The vulnerability can only be exploited when the BuddyPress plugin is also installed and activated.
27/02/2025
27/02/2025
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Gravedad 3.1 (CVSS 3.1 Base Score)
8.80
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
HIGH
Referencias
http://localhost:1337/wp-content/plugins/templines-helper-core/youzify/youzify.php#L3082
https://www.wordfence.com/threat-intel/vulnerabilities/id/8c5aa062-b9a2-4ddb-a5bf-4c8368218e85?source=cve
Enviar en el boletín
Off