Insecure Direct Object Reference Vulnerability in Binary MLM Plan Plugin for WordPress
CVE-2025-11895
4.3MEDIUM
What is CVE-2025-11895?
The Binary MLM Plan plugin for WordPress has a vulnerability that allows unauthorized access to sensitive payout records. This stems from the bmp_user_payout_detail_of_current_user() function which retrieves payout details based only on an identifier without checking if the authenticated user has the right to access those records. As a result, users with the bmp_user role, typically subscribers, can exploit this by manipulating requests to the /bmp-account-detail/ endpoint, potentially exposing other members' payout summaries. This lack of access control could lead to significant privacy issues for users relying on this feature.
Affected Version(s)
Binary MLM Plan * <= 3.0