Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-10038

Опубликовано: 15 окт. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266

Связанные уязвимости

CVSS3: 6.5
github
4 месяца назад

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

EPSS

Процентиль: 27%
0.00096
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-266