
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14162 is a Cross-Site Request Forgery (CSRF) vulnerability in the BMLT WordPress Plugin (Basic Meeting List Toolbox) affecting all versions up to and including 3.11.4. The flaw allows unauthenticated attackers to create or delete plugin settings by tricking a logged-in site administrator into clicking a malicious link. It was published on December 12, 2025, and assigned a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is missing nonce validation on the BMLTPlugin_create_option and BMLTPlugin_delete_option WordPress admin actions, classified as CWE-352 (Cross-Site Request Forgery). Because these actions lack proper CSRF tokens, any forged HTTP request that originates from a browser session authenticated as a site administrator will be accepted and processed by WordPress. An attacker crafts a malicious page or link that, when visited by an administrator, silently submits a forged form or request to the vulnerable endpoints, manipulating plugin configuration without the administrator's knowledge. The vulnerable code is visible in the plugin's source at bmlt-cms-satellite-plugin.php around line 848 (Wordfence, ENISA EUVD).
Successful exploitation allows an attacker to create or delete BMLT plugin settings on the affected WordPress site, potentially altering the plugin's behavior and disrupting meeting list functionality. The impact is limited to integrity — there is no direct confidentiality or availability impact — but manipulated settings could redirect users to attacker-controlled BMLT root servers or degrade site functionality. The attack requires social engineering of an administrator and does not grant remote code execution or access to sensitive data (Wordfence).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-14162. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction — specifically, tricking a site administrator into clicking a crafted link — which limits its practical exploitability (Wordfence, Red Hat CVE).
BMLTPlugin_create_option or BMLTPlugin_delete_option action with attacker-chosen parameter values./wp-admin/admin-post.php or similar endpoints with action=BMLTPlugin_create_option or action=BMLTPlugin_delete_option parameters originating from unusual referrers or external domains.wp_options) for unexpected BMLT-related entries added at unusual times.WordPress site administrators should update the BMLT WordPress Plugin to version 3.11.5 or later, which addresses the missing nonce validation. Until patching is possible, administrators should exercise caution when clicking links from untrusted sources while logged into their WordPress dashboard, and consider using browser extensions that block cross-site form submissions. No additional configuration-based workaround has been published by the vendor (Wordfence, ENISA EUVD).
The vulnerability was discovered and reported by Wordfence, which published the advisory on December 12, 2025. No significant broader media coverage, notable researcher commentary, or community discussion beyond standard vulnerability database aggregation has been observed for this low-severity issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."