Unauthorized Data Modification in Traffic Monitor Plugin for WordPress
CVE-2025-5815
5.3MEDIUM
What is CVE-2025-5815?
The Traffic Monitor plugin for WordPress contains a vulnerability that enables unauthorized data modification due to a missing capability check in the tfcm_maybe_set_bot_flags() function. This oversight affects all versions up to and including 3.2.2, allowing unauthenticated attackers to disable bot logging, thereby compromising the integrity of monitoring features within the plugin.
Affected Version(s)
Traffic Monitor * <= 3.2.2