Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10038

Опубликовано: 15 окт. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

EPSS

Процентиль: 32%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.5
github
6 месяцев назад

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

EPSS

Процентиль: 32%
0.00124
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266