
CVE-2025-15476 The The Bucketlister plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bucketlister_do_admin_ajax() fun… https://www.cve.org/CVERecord?id=CVE-2025-15476
Post summary
The Bucketlister WordPress plugin suffers from a missing capability check on the bucketlister_do_admin_ajax() function, enabling unauthorized data modification (CVE-2025-15476).
