CVE-2025-10038Medium· 6.5▾ SunlitThe Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-59134High· 8.8Incorrect Privilege Assignment vulnerability in Jthemes Sale! Immigration law, Visa services support, Migration Agent Consulting immiex allows Privilege Escalation.This issue affects Sale! Immigration law, Visa services support, Migratio…
CVE-2025-14660Medium· 5.6A flaw has been found in DecoCMS Mesh up to 1.0.0-alpha.31
CVE-2025-53428High· 8.8Incorrect Privilege Assignment vulnerability in N-Media Simple User Registration wp-registration allows Privilege Escalation.This issue affects Simple User Registration: from n/a through <= 6.8.
CVE-2025-11080Medium· 4.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4
CVE-2025-10819Medium· 4.3A security vulnerability has been detected in fuyang_lipengjun platform 1.0
CVE-2025-10277Medium· 6.3A vulnerability was detected in YunaiV yudao-cloud up to 2025.09