PT-2025-17716 · WordPress · Flynax Bridge

Kenneth Dunn

·

Published

2025-04-24

·

Updated

2026-04-08

·

CVE-2025-3603

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flynax Bridge plugin for WordPress versions up to and including 2.2.0
Description The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover. This issue arises because the plugin does not properly validate a user's identity before updating their details, such as the password. As a result, unauthenticated attackers can change arbitrary users' passwords, including those of administrators, and leverage this to gain access to their accounts.
Recommendations For versions up to and including 2.2.0, update to a version later than 2.2.0 to resolve the issue. As a temporary workaround, consider restricting access to the plugin's user update functionality until a patch is available. Avoid using the plugin's password update feature for any user accounts until the issue is resolved.

Fix

LPE

Weakness Enumeration

Related Identifiers

CVE-2025-3603

Affected Products

Flynax Bridge