CWE-269— Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.— MITRE CWE catalog
4,937 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-269page 78 of 99
- CVE-2025-0651HIGHCVSS 7.1EG 7.12025-01-22
Improper Privilege Management vulnerability in Cloudflare WARP on Windows allows File Manipulation. User with a low system privileges can create a set of symlinks inside the C:\ProgramData\Cloudflare\warp-diag-partials folder. After tr…
- CVE-2025-0834HIGHCVSS 7.8EG 7.82025-01-30
Privilege escalation vulnerability has been found in Wondershare Dr.Fone version 13.5.21. This vulnerability could allow an attacker to escalate privileges by replacing the binary ‘C:\ProgramData\Wondershare\wsServices\ElevationService.e…
- CVE-2025-0893HIGHCVSS 7.8EG 7.82025-02-19
Symantec Diagnostic Tool (SymDiag), prior to 3.0.79, may be susceptible to a Privilege Escalation vulnerability.
- CVE-2025-1037HIGHCVSS 7.5EG 7.52025-10-28
By making minor configuration changes to the TropOS 4th Gen device, an authenticated user with the ability to run user level shell commands can enable access via secure shell (SSH) to an unrestricted root shell. This is possible through ab…
- CVE-2025-10578HIGHCVSS 7.8EG 7.82025-10-01
A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.47.41.0. The vulnerability could potentially allow a local attacker to escalate privileges via an arbitrary file write.
- CVE-2025-10650LOWCVSS 1.8EG 1.82025-09-18
SoftIron HyperCloud 2.5.0 through 2.6.3 may incorrectly add user SSH keys to the administrator-level authorized keys under certain conditions, allowing unauthorized privilege escalation to admin via SSH. Affects non-production debug and i…
- CVE-2025-10657HIGHCVSS 8.7EG 8.72025-09-26
In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/hardened-desktop/enhanced-container-isolation/ ) enabled, an administrator can utilize the command restrictions feature …
- CVE-2025-11086HIGHCVSS 8.1EG 8.12025-10-22
The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.7. This is due to the plugin not properly validating a user's rol…
- CVE-2025-11168HIGHCVSS 8.8EG 8.82025-11-11
The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5. This is due to plugin not properly handling the user switch back function. This makes it possible for authenticated a…
- CVE-2025-1121MEDIUMCVSS 6.8EG 6.82025-03-07
Privilege escalation in Installer and Recovery image handling in Google ChromeOS version 15786.48.2 on device allows an attacker with physical access to gain root code execution and potentially unenroll enterprise-managed devices via a sp…
- CVE-2025-11457CRITICALCVSS 9.8EG 9.82025-11-11
The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privilege Escalation in versions 0.9.0-beta2 to 1.8.2. This is due to the /easycommerce/v1/orders REST API endpoint not prop…
- CVE-2025-11533CRITICALCVSS 9.8EG 9.82025-10-11
The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. This is due to the process_register() function not restricting what user roles a user can register with. This makes it p…
- CVE-2025-11561HIGHCVSS 8.8EG 8.82025-10-09
A flaw was found in the integration of Active Directory and the System Security Services Daemon (SSSD) on Linux systems. In default configurations, the Kerberos local authentication plugin (sssd_krb5_localauth_plugin) is enabled, but a fal…
- CVE-2025-11923HIGHCVSS 8.8EG 8.82025-11-13
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalation. This is due to the plugin not properly validating a user's identity prior to allowing them to modify their own ro…
- CVE-2025-12381HIGHCVSS 7.8EG 7.82025-12-09
Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, Parameter Injection. A local user with access to the command line may escalate their privileges by abusing the paramet…
- CVE-2025-12405HIGHCVSS 7.7EG 7.72025-11-10
An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Looker Studio user with report view access could make a copy of the report and execute arbitrary SQL that would run on th…
- CVE-2025-12424CRITICALCVSS 9.8EG 9.82025-10-28
Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
- CVE-2025-12425HIGHCVSS 7.8EG 7.82025-10-28
Local Privilege Escalation.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
- CVE-2025-12485HIGHCVSS 8.8EG 8.82025-11-06
Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated user to impersonate another account by replaying the pre-MFA cookie.This does not bypass the target account MFA verifi…
- CVE-2025-12683MEDIUMCVSS 5.8EG 5.82025-11-04
The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named pipe. The named pipe has a NULL DACL and thus provides all users full permission over it; leading to potential Service…
- CVE-2025-12726HIGHCVSS 7.5EG 7.52025-11-10
Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severi…
- CVE-2025-12882CRITICALCVSS 9.8EG 9.82026-02-19
The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. This is due to the plugin allowing users who are registering new accounts to set their own role by supplying the 'listi…
- CVE-2025-1295HIGHCVSS 8.8EG 8.82025-02-27
The Templines Elementor Helper Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.7. This is due to allowing arbitrary user meta updates. This makes it possible for authenticated attacke…
- CVE-2025-12952HIGHCVSS 8.7EG 8.72025-12-10
A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook editor permission are able to configure Webhooks using Dialogflow service agent access token authentication. This allow…
- CVE-2025-12981CRITICALCVSS 9.8EG 9.82026-02-27
The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user registration function that fails to properl…
- CVE-2025-13176HIGHCVSS 8.4EG 8.42026-01-30
Planting a custom configuration file in ESET Inspect Connector allow load a malicious DLL.
- CVE-2025-13292HIGHCVSS 7.6EG 7.62025-12-06
A vulnerability in Apigee-X allowed an attacker to gain unauthorized read and write access to Apigee Analytics (AX) data and access logs belonging to other Apigee customer organizations. Apigee-X was found to be vulnerable. This vulnerab…
- CVE-2025-13534MEDIUMCVSS 6.3EG 6.32025-12-02
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX actio…
- CVE-2025-13538CRITICALCVSS 9.8EG 9.82025-11-27
The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.5. This is due to the 'findall_listing_user_registration_additional_params' function not restricting what user roles a…
- CVE-2025-13540CRITICALCVSS 9.8EG 9.82025-11-27
The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This is due to the 'tiare_membership_init_rest_api_register' function not restricting what user roles a user can reg…
- CVE-2025-13542CRITICALCVSS 9.8EG 9.82025-12-02
The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.4. This is due to the 'dtlms_register_user_front_end' function not restricting what user roles a user can register wi…
- CVE-2025-13559CRITICALCVSS 9.8EG 9.82025-11-25
The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'edukart_pro_register_user_front_end' function not restricting what user roles a user can register w…
- CVE-2025-13563CRITICALCVSS 9.8EG 9.82026-02-19
The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the 'lizza_lms_pro_register_user_front_end' function not restricting what user roles a user can regist…
- CVE-2025-13618CRITICALCVSS 9.8EG 9.82026-05-05
The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. This is due to the plugin not properly restricting the roles that users can register with in the mentoring_process_regist…
- CVE-2025-13619CRITICALCVSS 9.8EG 9.82025-12-20
The Flex Store Users plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.0. This is due to the 'fsUserHandle::signup' and the 'fsSellerRole::add_role_seller' functions not restricting what u…
- CVE-2025-13675CRITICALCVSS 9.8EG 9.82025-11-27
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the 'paypal-submit.php' file not restricting what user roles a user can register with. This makes it possible…
- CVE-2025-13680HIGHCVSS 8.8EG 8.82025-11-27
The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This is due to the plugin allowing a user to update the user role through the $user->set_role() function. This makes it poss…
- CVE-2025-13764CRITICALCVSS 9.8EG 9.82025-12-11
The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16. This is due to the 'WP_CarDealer_User::process_register' function not restricting what user roles a user can register…
- CVE-2025-13787MEDIUMCVSS 5.4EG 5.42025-11-30
A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/file/control.php of the component File Handler. Executing manipulation of the argument fileID can lead to improper priv…
- CVE-2025-13851CRITICALCVSS 9.8EG 9.82026-02-19
The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user registration in all versions up to, and including, 1.0.7. This is due to the plugin not validating or restricting the use…
- CVE-2025-13917HIGHCVSS 7.0EG 7.02026-01-28
WSS Agent, prior to 9.8.5, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally…
- CVE-2025-13918MEDIUMCVSS 6.7EG 6.72026-01-28
Symantec Endpoint Protection, prior to 14.3 RU10 Patch 1, RU9 Patch 2, and RU8 Patch 3, may be susceptible to a Elevation of Privilege vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software appli…
- CVE-2025-1424HIGHCVSS 8.6EG 8.62025-03-04
A privilege escalation vulnerability in PocketBook InkPad Color 3 allows attackers to escalate to root privileges if they gain physical access to the device. This issue affects InkPad Color 3 in version U743k3.6.8.3671.
- CVE-2025-1425MEDIUMCVSS 4.7EG 4.72025-03-04
A Sudo privilege misconfiguration vulnerability in PocketBook InkPad Color 3 on Linux, ARM allows attackers to read file contents on the device.This issue affects InkPad Color 3: U743k3.6.8.3671.
- CVE-2025-14252HIGHCVSS 7.8EG 7.82025-12-16
An Improper Access Control vulnerability in Advantech SUSI driver (susi.sys) allows attackers to read/write arbitrary memory, I/O ports, and MSRs, resulting in privilege escalation, arbitrary code execution, and information disclosure. Thi…
- CVE-2025-14533CRITICALCVSS 9.8EG 9.82026-01-20
The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 0.9.2.1. This is due to the 'insert_user' function not restricting the roles with which a user can regist…
- CVE-2025-14736CRITICALCVSS 9.8EG 9.82026-01-09
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.28.29. This is due to insufficient validation of user-supplied role values in the 'validate_value', 'pre_up…
- CVE-2025-14817MEDIUMCVSS 6.5EG 6.52025-12-17
The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission control and can be accessed by third-party apps which can construct intents to directly open adb debugging functionality with…
- CVE-2025-14975HIGHCVSS 8.1EG 8.12026-01-29
The Custom Login Page Customizer WordPress plugin before 2.5.4 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, …
- CVE-2025-15027CRITICALCVSS 9.8EG 9.82026-02-08
The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.6.03. This is due to the plugin allowing a user to update arbitrary user meta through the 'jay_login_register_ajax_…
Map vulnerabilities like CWE-269 to your infrastructure
EchelonGraph correlates every CVE — across CWE-269 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →