
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-15476 is a Missing Authorization vulnerability in the Bucketlister plugin for WordPress, allowing authenticated attackers with Subscriber-level access or above to perform unauthorized modification of bucket list data. It affects all versions of the plugin up to and including 0.1.5. The vulnerability was published on February 7, 2026, and was discovered and reported by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).
The root cause is a missing capability check (CWE-862) on the bucketlister_do_admin_ajax() function within the plugin's AJAX handler. Because no authorization check is enforced before processing the request, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can invoke this function to add, delete, or modify arbitrary bucket list items. The vulnerable code is visible in the plugin source at bucketlister.php line 185 (Wordfence, Plugin Source).
Successful exploitation allows authenticated low-privileged users to add, delete, or modify arbitrary bucket list items managed by the plugin, resulting in unauthorized data integrity violations. There is no confidentiality or availability impact, and the scope is limited to the plugin's data within the affected WordPress installation. The risk is primarily data tampering by any registered user on the site (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level account on the target WordPress site (Wordfence).
/wp-admin/admin-ajax.php) with the appropriate action parameter targeting bucketlister_do_admin_ajax()./wp-admin/admin-ajax.php from low-privileged user accounts, particularly with action parameters related to bucketlister_do_admin_ajax.Site administrators should update the Bucketlister plugin to version 0.1.6 or later, which addresses the missing capability check. If an immediate update is not possible, consider disabling the plugin until patching can be performed. Additionally, restricting open user registration on WordPress sites reduces the attack surface by limiting who can obtain Subscriber-level access (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."