Critical
Low
Medium
CVE-2025-11895
Overview
The Binary MLM Plan plugin for WordPress is vulnerable to insecure direct object reference in versions up to, and including, 3.0. This is due to the bmp_user_payout_detail_of_current_user() function selecting payout records solely by id without verifying ownership. This makes it possible for authent...
Critical
Low
Medium
No items found.