CVE-2025-10038

Binary MLM Plan <= 3.0 - Unauthenticated Limited Privilege Escalation

mediumIncorrect Privilege Assignment
6.5
CVSS Score
6.5
CVSS Score
medium
Severity
5.0
Patched in
23d
Time to patch

Description

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Low
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=3.0
PublishedOctober 14, 2025
Last updatedNovember 6, 2025
Affected pluginbinary-mlm-plan

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.