CVE-2025-6042 HIGH

CVE-2025-6042: Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme <= 1.4.0 - Unauthenticated Privilege Escalation to Editor

Vendor Pebas
Product Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme
Weakness CWE-269
Published October 15, 2025
Last update April 8, 2026

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

The Lisfinity Core - Lisfinity Core plugin used for pebas® Lisfinity WordPress theme plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.4.0. This is due to the plugin assigning the editor role by default. While limitations with respect to capabilities are put in place, use of the API is not restricted. This vulnerability can be leveraged together with CVE-2025-6038 to obtain admin privileges.

Explanation of Vulnerability in Simple Terms

02Summary

The Lisfinity Core WordPress plugin through version 1.4.0 contains a privilege management flaw that allows unauthenticated attackers to read sensitive data, modify content, or disrupt site availability. The vulnerability requires no user interaction and can be exploited over the network. Site administrators should update the plugin immediately to a version newer than 1.4.0.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify site content, or cause the site to become unavailable without needing to log in.

Potential impact on your site

04Site Impact

Unauthorized users can access private information, alter pages/posts, or disrupt site operations without credentials.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

October 15, 2025 CVE published
April 8, 2026 Record updated