CVE-2025-8899
8.8VideoWhisper · Paid Videochat Turnkey Site – HTML5 PPV Live Webcams
The VideoWhisper Paid Videochat Turnkey Site plugin for WordPress is vulnerable to privilege escalation in versions up to 7.3.20 due to improper capability checks in the registration form function.
Executive summary
A critical privilege escalation vulnerability in the VideoWhisper Paid Videochat Turnkey Site plugin allows authenticated attackers to register unauthorized administrator accounts.
Vulnerability
The vulnerability resides in the videowhisper_register_form function, which fails to properly restrict the assignment of user roles during the registration process. An authenticated attacker with Author-level access or higher can exploit this to register a new account with administrator privileges.
Business impact
Successful exploitation grants an attacker full administrative control over the WordPress instance. This results in total compromise of site data, the ability to modify or delete content, and the potential for complete system takeover, which presents a severe risk to organizational operations and data integrity. The CVSS score of 8.8 reflects the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update the Paid Videochat Turnkey Site plugin to version 7.3.21 or later, as provided in the vendor patch.
Proactive Monitoring: Audit the WordPress user database for any unauthorized accounts with administrative privileges and review recent user registration logs for anomalous activity.
Compensating Controls: If an immediate update is not possible, consider deactivating the plugin or restricting access to registration pages via a Web Application Firewall (WAF) until the patch can be deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential privilege escalation, administrators must prioritize updating this plugin immediately. Organizations should verify their current version and apply the patch to prevent unauthorized account creation that could lead to a total site compromise.
More VideoWhisper CVEs
Sources
Originally found and disclosed by Peter Thaleikis, per the CVE Program record.