
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11895 is an Insecure Direct Object Reference (IDOR) vulnerability in the Binary MLM Plan plugin for WordPress, allowing authenticated attackers to access other users' payout data without authorization. It affects versions up to and including 5.0 (per NVD) or 3.0 (per ENISA/Wordfence). The vulnerability was published on October 17–18, 2025, with Wordfence credited as the assigner. It carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).
The root cause is an authorization bypass through a user-controlled key (CWE-639). The vulnerable bmp_user_payout_detail_of_current_user() function retrieves payout records by the payout-id parameter alone, without verifying that the requesting user owns the referenced record. An authenticated attacker with the bmp_user role (typically a subscriber-level account) can craft requests to the /bmp-account-detail/ endpoint with arbitrary payout-id values to enumerate and view other members' payout summaries, provided they have access to the shortcode output (Wordfence, ENISA EUVD).
Successful exploitation results in unauthorized disclosure of other MLM members' payout summaries, including potentially sensitive financial data such as earnings and transaction details. The impact is limited to confidentiality (low), with no integrity or availability impact. While lateral movement is not directly enabled, exposure of financial data could facilitate social engineering or targeted fraud against affected users (Red Hat CVE, Wordfence).
bmp_user (subscriber-level) account on the target site to gain authenticated access./bmp-account-detail/) to confirm access./bmp-account-detail/ with incrementing or guessed payout-id parameter values (e.g., ?payout-id=1, ?payout-id=2, etc.)./bmp-account-detail/ with sequentially or randomly varying payout-id parameter values from a single user session.bmp_user role) making numerous requests to the account detail endpoint with different payout-id values in a short time window.WordPress site administrators should update the Binary MLM Plan plugin to a version beyond 5.0 that includes a fix for this vulnerability, once a patched release is available from the vendor (letscms/mlmsoftwarez). As an interim workaround, restrict registration of bmp_user accounts to trusted individuals only, or temporarily disable the affected shortcode/endpoint if payout detail access is not critical. Monitor the plugin's official repository and the WordPress plugin directory for a patched release (Wordfence, WordPress Plugin Trac).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for October 13–19, 2025, noting it as part of a broader set of plugin disclosures (Wordfence Blog). No significant independent researcher commentary or notable media coverage beyond standard vulnerability aggregator listings has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."