Unauthorized Plugin Installation in Classified Pro Theme for WordPress
CVE-2025-10706
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 October 2025
What is CVE-2025-10706?
The Classified Pro theme for WordPress is susceptible to security issues due to a missing capability check in the 'cwp_addons_update_plugin_cb' function, which affects all versions up to and including 1.0.14. This flaw allows authenticated attackers with subscriber-level access or higher to install arbitrary plugins on the server hosting the affected site. This capability can lead to potential remote code execution, posing a significant risk to website integrity. It is essential to apply updates and mitigate this vulnerability promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ClassifiedPro - reCommerce WordPress Theme * <= 1.0.14
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved