CVE-2025-15476
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-15476 is a Missing Authorization vulnerability in the Bucketlister plugin for WordPress, allowing authenticated attackers with Subscriber-level access or above to perform unauthorized modification of bucket list data. It affects all versions of the plugin up to and including 0.1.5. The vulnerability was published on February 7, 2026, and was discovered and reported by Wordfence. It carries a CVSS v3.1 base score of 4.3 (Medium) (Wordfence, Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the bucketlister_do_admin_ajax() function within the plugin's AJAX handler. Because no authorization check is enforced before processing the request, any authenticated WordPress user — including those with the lowest default role (Subscriber) — can invoke this function to add, delete, or modify arbitrary bucket list items. The vulnerable code is visible in the plugin source at bucketlister.php line 185 (Wordfence, Plugin Source).

Impact

Successful exploitation allows authenticated low-privileged users to add, delete, or modify arbitrary bucket list items managed by the plugin, resulting in unauthorized data integrity violations. There is no confidentiality or availability impact, and the scope is limited to the plugin's data within the affected WordPress installation. The risk is primarily data tampering by any registered user on the site (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.026%, indicating a very low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level account on the target WordPress site (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Bucketlister plugin version 0.1.5 or earlier, using tools like WPScan or by checking the plugin version in the site's source or readme files.
  2. Obtain Subscriber Access: Register for a free account on the target WordPress site (if open registration is enabled) or use existing low-privileged credentials.
  3. Craft AJAX Request: Send an authenticated HTTP POST request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the appropriate action parameter targeting bucketlister_do_admin_ajax().
  4. Manipulate Bucket List Data: Include parameters in the request body to add, modify, or delete arbitrary bucket list items, bypassing any authorization controls since none are enforced by the function.
  5. Achieve Objective: Confirm unauthorized data changes are reflected in the application, demonstrating successful exploitation of the missing capability check (Wordfence, Plugin Source).

Indicators of compromise

  • Network: Unusual or repeated POST requests to /wp-admin/admin-ajax.php from low-privileged user accounts, particularly with action parameters related to bucketlister_do_admin_ajax.
  • Logs: WordPress access logs showing authenticated Subscriber-level users making AJAX requests to admin endpoints outside of normal usage patterns.
  • Application Data: Unexpected creation, modification, or deletion of bucket list items not attributable to administrative users.

Mitigation and workarounds

Site administrators should update the Bucketlister plugin to version 0.1.6 or later, which addresses the missing capability check. If an immediate update is not possible, consider disabling the plugin until patching can be performed. Additionally, restricting open user registration on WordPress sites reduces the attack surface by limiting who can obtain Subscriber-level access (Wordfence).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18603NONEN/A
  • cancel-order-request-woocommerce
NoYesAug 09, 2026
CVE-2026-18473NONEN/A
  • wpdirectorykit
NoYesAug 09, 2026
CVE-2026-18465NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18464NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18357NONEN/A
  • wpc-order-tip
NoYesAug 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management