Privilege Escalation Vulnerability in Mentoring Plugin for WordPress
CVE-2025-13618
9.8CRITICAL
What is CVE-2025-13618?
The Mentoring plugin for WordPress exhibits a privilege escalation vulnerability due to improper role restrictions in the mentoring_process_registration() function. This flaw allows unauthenticated users to register as administrators, compromising the site's integrity. All versions up to and including 1.2.8 are affected, posing a significant risk if exploited. Administrators are advised to update to the latest version to mitigate this security concern.
Affected Version(s)
Mentoring 0 <= 1.2.8