CVE-2025-11533: WP Freeio <= 1.2.21 - Unauthenticated Privilege Escalation
The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the processregister() function not restricting what user roles a user can register with. This makes it possible for unauthenticated attackers to supply the 'administrator' role during registration and gain administrator access to the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11533?
The severity of CVE-2025-11533 is considered high due to the potential for privilege escalation.
How do I fix CVE-2025-11533?
To fix CVE-2025-11533, update the WP Freeio plugin to version 1.2.22 or later.
What systems are affected by CVE-2025-11533?
CVE-2025-11533 affects all versions of the WP Freeio plugin up to and including 1.2.21.
Can unauthenticated attackers exploit CVE-2025-11533?
Yes, unauthenticated attackers can exploit CVE-2025-11533 to gain unauthorized user roles.
What action should I take if I am using an affected version of WP Freeio?
If you are using an affected version of WP Freeio, it is essential to update to the latest version immediately to mitigate the vulnerability.