Privilege Escalation in Lisfinity Core Plugin for WordPress from Lisfinity
CVE-2025-6042
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 October 2025
What is CVE-2025-6042?
The Lisfinity Core plugin, part of the Lisfinity WordPress theme, has a vulnerability that allows for privilege escalation in all versions up to and including 1.4.0. By default, this plugin assigns the editor role, which, while imposed with certain limitations regarding capabilities, does not adequately restrict API usage. This flaw can potentially be exploited in conjunction with other vulnerabilities to grant unauthorized admin privileges, putting WordPress sites at significant risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme * <= 1.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved