CVE-2025-12391
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-11-18

Last updated on: 2026-04-08

Assigner: Wordfence

Description
The Restrictions for BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the handle_optin_optout() function in all versions up to, and including, 1.5.2. This makes it possible for unauthenticated attackers to opt in and out of tracking.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-11-18
Last Modified
2026-04-08
Generated
2026-05-07
AI Q&A
2025-11-18
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wordpress buddypress *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

The Restrictions for BuddyPress plugin for WordPress has a vulnerability due to a missing capability check in the handle_optin_optout() function in all versions up to 1.5.2. This allows unauthenticated attackers to modify data by opting users in or out of tracking without authorization.


How can this vulnerability impact me? :

This vulnerability can allow unauthorized attackers to change tracking preferences for users without their consent, potentially leading to privacy violations and manipulation of tracking data.


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, update the Restrictions for BuddyPress plugin to a version later than 1.5.2 where the missing capability check on the handle_optin_optout() function is fixed. Until then, restrict access to the plugin's functionality to authenticated and authorized users only, and monitor for any unauthorized opt-in or opt-out activity.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart