Flynax develops the Bridge product, a web-based platform for managing online marketplaces and classified listings, where the observed vulnerability exposure centers on access-control failures including missing authorization checks and unverified password-change operations. These weakness patterns reflect gaps in authentication and session-management logic that are characteristic of web application frameworks handling user privilege boundaries. Current CVE counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flynax over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-3604CRITICAL The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properl | Apr 24, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-3603CRITICAL The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.2.0. This is due to the plugin not properl | Apr 24, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-4179HIGH The Flynax Bridge plugin for WordPress is vulnerable to limited Privilege Escalation due to a missing capability check on the registerUser() function in all versions up to, and inc | May 2, 2025 | 7.3 | 22 | NO | NO |
CVE-2025-4177MEDIUM The Flynax Bridge plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteUser() function in all versions up to, and includin | May 2, 2025 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flynax.
Media articles that mention a CVE ID that affects a product developed by Flynax — matched by CVE ID, not by vendor name.