Description

The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and including, 3.0. This is due to bmp_user role granting all users with the manage_bmp capability by default upon registration through the plugin's form. This makes it possible for unauthenticated attackers to register and manage the plugin's settings.

INFO

Published Date :

2025-10-15T08:25:57.132Z

Last Modified :

2026-04-08T17:02:09.537Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-10038 vulnerability.

Vendors Products
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact