Unauthorized Data Modification in Administrator Z Plugin for WordPress
CVE-2025-2815

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
28 March 2025

What is CVE-2025-2815?

The Administrator Z plugin for WordPress has a significant vulnerability due to a missing capability check in the adminz_import_backup() function. This flaw allows authenticated users with Subscriber-level access and higher to modify data on the WordPress site. Attackers can exploit this weakness to change critical settings, such as the default registration role to administrator, effectively enabling unauthorized user registrations. As a result, attackers could gain administrative access, posing serious security risks to vulnerable WordPress sites.

Affected Version(s)

Administrator Z * <= 2025.03.24

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.