Privilege Escalation Vulnerability in aapanel WP Toolkit for WordPress
CVE-2025-6813
8.8HIGH
What is CVE-2025-6813?
The aapanel WP Toolkit plugin for WordPress is susceptible to a serious privilege escalation flaw, specifically within the auto_login() function. This vulnerability arises from the absence of proper authorization checks, permitting authenticated users with Subscriber-level roles or higher to circumvent standard role restrictions. As a result, these users can gain unauthorized admin privileges, posing a significant risk to WordPress installations using this plugin.
Affected Version(s)
aapanel WP Toolkit 1.0 <= 1.1