PT-2025-47278 · Unknown+1 · Buddypress+1

Abhirup Konwar

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-12391

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions BuddyPress Restrictions plugin for WordPress versions up to and including 1.5.2
Description The Restrictions for BuddyPress plugin for WordPress is susceptible to unauthorized data modification. A missing capability check within the handle optin optout() function allows unauthenticated attackers to control tracking preferences, opting in and out without authorization.
Recommendations Update BuddyPress Restrictions plugin to a version later than 1.5.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12391

Affected Products

Buddypress
Restrictions For Buddypress