CVE-2025-28874 MEDIUM

CVE-2025-28874: WordPress BP Email Assign Templates By shanebp plugin <= 1.7 - Arbitrary Content Deletion vulnerability

Vendor Shanebp
Product BP Email Assign Templates
Weakness CWE-639 · IDOR
Published March 11, 2025
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in shanebp BP Email Assign Templates bp-email-assign-templates allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects BP Email Assign Templates: from n/a through <= 1.7.

Explanation of Vulnerability in Simple Terms

02Summary

BP Email Assign Templates versions 1.7 and earlier contain an authorization flaw that allows high-privilege users to modify site data without proper access controls. An authenticated administrator can alter email templates and assignments in ways that affect site integrity and availability. The vulnerability requires administrative credentials to exploit.

What an attacker can do

03Attacker Capabilities

Modify email templates and assignments, disrupting site functionality and data integrity.

Potential impact on your site

04Site Impact

Administrators with malicious intent or compromised admin accounts can alter critical email configurations, potentially disrupting communications and site operations.

Conditions required to exploit

05Prerequisites

Attacker must have high-level administrative privileges on the site.

Key dates

06Disclosure timeline

March 11, 2025 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE