The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.
History

Wed, 15 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Oct 2025 08:45:00 +0000

Type Values Removed Values Added
Description The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.
Title Binary MLM Plan <= 3.0 - Unauthenticated Limited Privilege Escalation
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2025-10-15T14:01:22.449Z

Reserved: 2025-09-05T17:35:09.789Z

Link: CVE-2025-10038

cve-icon Vulnrichment

Updated: 2025-10-15T14:01:18.007Z

cve-icon NVD

Status : Received

Published: 2025-10-15T09:15:36.167

Modified: 2025-10-15T09:15:36.167

Link: CVE-2025-10038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.