Unauthorized Plugin Installation in Classified Pro Theme for WordPress
CVE-2025-10706

8.8HIGH

What is CVE-2025-10706?

The Classified Pro theme for WordPress is susceptible to security issues due to a missing capability check in the 'cwp_addons_update_plugin_cb' function, which affects all versions up to and including 1.0.14. This flaw allows authenticated attackers with subscriber-level access or higher to install arbitrary plugins on the server hosting the affected site. This capability can lead to potential remote code execution, posing a significant risk to website integrity. It is essential to apply updates and mitigate this vulnerability promptly.

Affected Version(s)

ClassifiedPro - reCommerce WordPress Theme * <= 1.0.14

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.
CVE-2025-10706 : Unauthorized Plugin Installation in Classified Pro Theme for WordPress