Privilege Escalation Vulnerability in LC Wizard Plugin for WordPress
CVE-2025-5483
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 7 November 2025
What is CVE-2025-5483?
The LC Wizard plugin for WordPress contains a security flaw that allows unauthenticated users to escalate privileges. Specifically, a missing capability check in the ghl-wizard/inc/wp_user.php file enables unauthorized attackers to create new user accounts with administrative privileges if the PRO feature is activated. This could lead to further exploitation of the site.
Affected Version(s)
Connector Wizard (formerly LC Wizard) 1.2.10 <= 1.3.0