BP Email Assign Templates <= 1.7 - Authenticated (Admin+) Arbitrary Option Deletion

2025-03-11 00:00
ch4r0n

Strategic Overview

Status
Patched in 1.8
Affected Version<= 1.7
CVSS6.8Medium
CVECVE-2025-28874
View all BP Email Assign Templates vulnerabilities

Vulnerability Overview

The BP Email Assign Templates plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the delete_eto() function in all versions up to, and including, 1.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary site options.

Technical Analysis

REMEDIATION: Update to version 1.8, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C