Privilege Escalation in Tiger Theme for WordPress by ThemeForest
CVE-2025-13680

8.8HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
27 November 2025

What is CVE-2025-13680?

The Tiger theme for WordPress, utilized by many users, is susceptible to a vulnerability that enables authenticated attackers with Subscriber-level access and higher to elevate their privileges to that of an administrator. This critical flaw arises from the theme's use of the $user->set_role() function, which permits users to update roles without proper restrictions. As a result, it poses a significant risk, allowing attackers to gain unauthorized access to sensitive functionalities and content within the site.

Affected Version(s)

Tiger * <= 101.2.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.
CVE-2025-13680 : Privilege Escalation in Tiger Theme for WordPress by ThemeForest