Insecure Direct Object Reference Vulnerability in Binary MLM Plan Plugin for WordPress
CVE-2025-11895

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 October 2025

What is CVE-2025-11895?

The Binary MLM Plan plugin for WordPress has a vulnerability that allows unauthorized access to sensitive payout records. This stems from the bmp_user_payout_detail_of_current_user() function which retrieves payout details based only on an identifier without checking if the authenticated user has the right to access those records. As a result, users with the bmp_user role, typically subscribers, can exploit this by manipulating requests to the /bmp-account-detail/ endpoint, potentially exposing other members' payout summaries. This lack of access control could lead to significant privacy issues for users relying on this feature.

Affected Version(s)

Binary MLM Plan * <= 3.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-11895 : Insecure Direct Object Reference Vulnerability in Binary MLM Plan Plugin for WordPress