BP Email Assign Templates <= 1.7 - Authenticated (Admin+) Arbitrary Option Deletion
2025-03-11 00:00
ch4r0nStrategic Overview
StatusPatched in 1.8
Affected PluginBP Email Assign Templates
Affected Version
<= 1.7CVSS6.8Medium
CVE
CVE-2025-28874Vulnerability Overview
The BP Email Assign Templates plugin for WordPress is vulnerable to unauthorized loss of data due to insufficient validation on the delete_eto() function in all versions up to, and including, 1.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to delete arbitrary site options.
Technical Analysis
REMEDIATION: Update to version 1.8, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C