CVE-2025-3603
The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.53%
- CWE
- CWE-620
- Published
- 2025-04-24
- Last modified
- 2026-03-12
Affected products
- v1rustyle Flynax Bridge
Weakness type
Related vulnerabilities
- CVE-2024-12824 — Nokri – Job Board WordPress Theme <= 1.6.2 - Unauthenticated Arbitrary Password Change
- CVE-2025-4322 — Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover
- CVE-2024-20419 — A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauth
- CVE-2025-1107 — Unverified password change vulnerability in Janto
- CVE-2024-33699 — The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers t
- CVE-2024-12860 — CarSpot – Dealership Wordpress Classified Theme <= 2.4.3 - Unauthenticated Arbitrary Password Reset/Account Takeover
- CVE-2025-4558 — WormHole Tech GPM - Unverified Password Change
- CVE-2025-2253 — IMITHEMES Listing <= 3.3 - Unauthenticated Privilege Escalation via Unverified Password Reset