{"api_version":"1","generated_at":"2026-07-23T13:40:31+00:00","cve":"CVE-2025-3604","urls":{"html":"https://cve.report/CVE-2025-3604","api":"https://cve.report/api/cve/CVE-2025-3604.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-3604","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-3604"},"summary":{"title":"Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover","description":"The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.","state":"PUBLISHED","assigner":"Wordfence","published_at":"2025-04-24 09:15:31","updated_at":"2026-04-08 18:24:43"},"problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"3.1","source":"security@wordfence.com","type":"Secondary","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"9.8","severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/935caa43-4c75-47ad-a631-63988e21f834?source=cve","name":"https://www.wordfence.com/threat-intel/vulnerabilities/id/935caa43-4c75-47ad-a631-63988e21f834?source=cve","refsource":"security@wordfence.com","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/changeset/3306501/","name":"https://plugins.trac.wordpress.org/changeset/3306501/","refsource":"security@wordfence.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/request.php","name":"https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/request.php","refsource":"security@wordfence.com","tags":["Product"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-3604","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-3604","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"v1rustyle","product":"Flynax Bridge","version":"affected 2.2.0 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2025-04-23T19:43:51.000Z","lang":"en","value":"Disclosed"}],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Kenneth Dunn","lang":"en"}],"nvd_cpes":[{"cve_year":"2025","cve_id":"3604","vulnerable":"1","versionEndIncluding":"2.2.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"flynax","cpe5":"flynax_bridge","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"3604","cve":"CVE-2025-3604","epss":"0.008350000","percentile":"0.746130000","score_date":"2026-04-08","updated_at":"2026-04-09 00:05:10"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-3604","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2025-04-24T13:56:02.330253Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2025-04-24T13:56:54.288Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Flynax Bridge","vendor":"v1rustyle","versions":[{"lessThanOrEqual":"2.2.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Kenneth Dunn"}],"descriptions":[{"lang":"en","value":"The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account."}],"metrics":[{"cvssV3_1":{"baseScore":9.8,"baseSeverity":"CRITICAL","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-04-08T17:09:39.913Z","orgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","shortName":"Wordfence"},"references":[{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/935caa43-4c75-47ad-a631-63988e21f834?source=cve"},{"url":"https://plugins.trac.wordpress.org/browser/flynax-bridge/trunk/request.php"},{"url":"https://plugins.trac.wordpress.org/changeset/3306501/"}],"timeline":[{"lang":"en","time":"2025-04-23T19:43:51.000Z","value":"Disclosed"}],"title":"Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover"}},"cveMetadata":{"assignerOrgId":"b15e7b5b-3da4-40ae-a43c-f7aa60e62599","assignerShortName":"Wordfence","cveId":"CVE-2025-3604","datePublished":"2025-04-24T08:23:49.297Z","dateReserved":"2025-04-14T19:34:06.967Z","dateUpdated":"2026-04-08T17:09:39.913Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2025-04-24 09:15:31","lastModifiedDate":"2026-04-08 18:24:43","problem_types":["CWE-862","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"security@wordfence.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:flynax:flynax_bridge:*:*:*:*:*:wordpress:*:*","versionEndIncluding":"2.2.0","matchCriteriaId":"F761DE48-B834-4006-8045-6CB005EB29EC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"3604","Ordinal":"1","Title":"Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation vi","CVE":"CVE-2025-3604","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"3604","Ordinal":"1","NoteData":"The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for unauthenticated attackers to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.","Type":"Description","Title":"Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation vi"}]}}}