CVE-2025-11895
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11895 is an Insecure Direct Object Reference (IDOR) vulnerability in the Binary MLM Plan plugin for WordPress, allowing authenticated attackers to access other users' payout data without authorization. It affects versions up to and including 5.0 (per NVD) or 3.0 (per ENISA/Wordfence). The vulnerability was published on October 17–18, 2025, with Wordfence credited as the assigner. It carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE, Wordfence).

Technical details

The root cause is an authorization bypass through a user-controlled key (CWE-639). The vulnerable bmp_user_payout_detail_of_current_user() function retrieves payout records by the payout-id parameter alone, without verifying that the requesting user owns the referenced record. An authenticated attacker with the bmp_user role (typically a subscriber-level account) can craft requests to the /bmp-account-detail/ endpoint with arbitrary payout-id values to enumerate and view other members' payout summaries, provided they have access to the shortcode output (Wordfence, ENISA EUVD).

Impact

Successful exploitation results in unauthorized disclosure of other MLM members' payout summaries, including potentially sensitive financial data such as earnings and transaction details. The impact is limited to confidentiality (low), with no integrity or availability impact. While lateral movement is not directly enabled, exposure of financial data could facilitate social engineering or targeted fraud against affected users (Red Hat CVE, Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Binary MLM Plan plugin (versions ≤ 5.0) by inspecting page source for plugin-specific shortcodes or assets, or using tools like WPScan.
  2. Account Registration: Register or obtain a bmp_user (subscriber-level) account on the target site to gain authenticated access.
  3. Access Shortcode Output: Navigate to a page containing the Binary MLM Plan shortcode output (e.g., the account detail page at /bmp-account-detail/) to confirm access.
  4. Enumerate Payout IDs: Send authenticated GET or POST requests to /bmp-account-detail/ with incrementing or guessed payout-id parameter values (e.g., ?payout-id=1, ?payout-id=2, etc.).
  5. Extract Payout Data: Review the responses for payout summaries belonging to other users, capturing financial details such as earnings, transaction amounts, or member identifiers (Wordfence, ENISA EUVD).

Indicators of compromise

  • Network: Repeated authenticated requests to /bmp-account-detail/ with sequentially or randomly varying payout-id parameter values from a single user session.
  • Logs: WordPress access logs showing a single authenticated user (bmp_user role) making numerous requests to the account detail endpoint with different payout-id values in a short time window.
  • Application Behavior: Payout detail pages returning data for users other than the currently logged-in session owner, observable in server-side logging if request/response logging is enabled.

Mitigation and workarounds

WordPress site administrators should update the Binary MLM Plan plugin to a version beyond 5.0 that includes a fix for this vulnerability, once a patched release is available from the vendor (letscms/mlmsoftwarez). As an interim workaround, restrict registration of bmp_user accounts to trusted individuals only, or temporarily disable the affected shortcode/endpoint if payout detail access is not critical. Monitor the plugin's official repository and the WordPress plugin directory for a patched release (Wordfence, WordPress Plugin Trac).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for October 13–19, 2025, noting it as part of a broader set of plugin disclosures (Wordfence Blog). No significant independent researcher commentary or notable media coverage beyond standard vulnerability aggregator listings has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15991HIGH8.8
  • file-manager
NoYesAug 06, 2026
CVE-2026-15459HIGH8.1
  • wpmudev-updates
NoYesAug 06, 2026
CVE-2026-7529HIGH7.5
  • wisecampaign
NoYesAug 05, 2026
CVE-2026-18325HIGH7.2
  • forminator
NoYesAug 06, 2026
CVE-2026-16636HIGH7.2
  • fluent-smtp
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management