SB2025050539 - Multiple vulnerabilities in Flynax Bridge plugin for WordPress
Published: May 5, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Missing Authorization (CVE-ID: CVE-2025-4179)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to a missing capability check on the registerUser() function. A remote attacker can register new user accounts as authors.
2) Missing Authorization (CVE-ID: CVE-2025-4177)
The vulnerability allows a remote attacker to bypass authorization checks.
The vulnerability exists due to a missing capability check on the deleteUser() function. A remote attacker can delete arbitrary users.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.
References
- https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/src/API.php#L288
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a2447cf4-0261-4ef2-98ec-98fa02dc8b87?source=cve
- https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/src/API.php#L386
- https://www.wordfence.com/threat-intel/vulnerabilities/id/dcb33d02-d384-4dff-91e1-c49e86b97d6e?source=cve