CVE-2025-67931

7.5

AITpro · BulletProof Security

A vulnerability in the AITpro BulletProof Security plugin allows unauthenticated attackers to retrieve sensitive data due to improper information handling in sent data.

Executive summary

A critical information exposure vulnerability in the AITpro BulletProof Security plugin allows unauthenticated attackers to access sensitive system data.

Vulnerability

The flaw is categorized as an Insertion of Sensitive Information Into Sent Data (CWE-201), where the application transmits sensitive details without proper authorization. The CVSS vector confirms the vulnerability is exploitable by an unauthenticated attacker over the network with no user interaction required.

Business impact

The ability for unauthorized actors to retrieve sensitive data poses a significant risk to organizational confidentiality. A successful exploit could lead to the exposure of proprietary system information, credentials, or configuration details, potentially facilitating further attacks. With a CVSS score of 7.5, this high severity vulnerability warrants immediate attention to prevent unauthorized data exfiltration.

Remediation

Immediate Action: Review the official Patchstack advisory for updates and apply the latest version of the BulletProof Security plugin as soon as a fix is released.

Proactive Monitoring: Audit server access logs for anomalous requests to the plugin endpoints and monitor for unexpected data egress patterns.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to filter or block suspicious requests directed at the plugin that match the identified sensitive data retrieval patterns.

Exploitation status

Public Exploit Available: No (exploit_available: unknown).

Analyst recommendation

Given the high severity and the ease of exploitation, security teams must prioritize the remediation of this vulnerability. Organizations should verify their current plugin version and prepare to update immediately once the vendor provides a patch. Until an update is applied, ensure that access to the WordPress administrative environment is restricted to authorized personnel only.

Sources

Originally found and disclosed by Nabil Irawan | Patchstack Bug Bounty Program, per the CVE Program record.