← WordPress Vulnerabilities
WordPress security by component

BMLT

BMLT is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Dec 12, 2025; the highest published CVSS base score is 4.3.

Plugin slug: bmlt-wordpress-satellite-plugin

CVE-2025-14162: BMLT: Cross-site request forgery

BMLT is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedDec 12, 2025
Safe version guidanceSee mitigation notes
Published vulnerabilities for bmlt-wordpress-satellite-plugin
Safe version
Dec 12, 2025 CVE-2025-14162
BMLT: Cross-site request forgery
BMLT is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.3
NVDPending