Unauthorized Data Modification in Administrator Z Plugin for WordPress
CVE-2025-2815
What is CVE-2025-2815?
The Administrator Z plugin for WordPress has a significant vulnerability due to a missing capability check in the adminz_import_backup() function. This flaw allows authenticated users with Subscriber-level access and higher to modify data on the WordPress site. Attackers can exploit this weakness to change critical settings, such as the default registration role to administrator, effectively enabling unauthorized user registrations. As a result, attackers could gain administrative access, posing serious security risks to vulnerable WordPress sites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Administrator Z * <= 2025.03.24
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved