๐Ÿ” CVE Alert

CVE-2025-11895

MEDIUM 4.3

Binary MLM Plan <= 5.0 - Authenticated (Subscriber+) Insecure Direct Object Reference

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 5.0. This is due to the bmp_user_payout_detail_of_current_user() function selecting payout records solely by id without verifying ownership. This makes it possible for authenticated attackers with the bmp_user role (often subscribers) to view other members' payout summaries via direct requests to the /bmp-account-detail/ endpoint with a crafted payout-id parameter granted they can access the shortcode output.

CWE CWE-639
Vendor letscms
Product binary mlm plan
Published Oct 17, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for letscms binary mlm plan

Be the first to know when new medium vulnerabilities affecting letscms binary mlm plan are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

letscms / Binary MLM Plan
0 โ‰ค 5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/adba7d0c-29ca-49c5-ac75-bb79d62f6107?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/binary-mlm-plan/trunk/includes/bmp-hook-functions.php#L833

Credits

Jonas Benjamin Friedli