Cross-Site Request Forgery in BMLT WordPress Plugin by WordPress
CVE-2025-14162
What is CVE-2025-14162?
The BMLT WordPress Plugin is susceptible to Cross-Site Request Forgery attacks. This vulnerability stems from a lack of nonce validation on actions such as 'BMLTPlugin_create_option' and 'BMLTPlugin_delete_option'. As a result, this flaw allows unauthenticated attackers to potentially alter plugin settings by tricking an administrator into performing unintended actions, such as clicking on malicious links. Website administrators are urged to assess their installations and apply necessary security measures to protect against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
BMLT WordPress Plugin * <= 3.11.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved