Логотип exploitDog
bind:CVE-2025-1475
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-1475

Количество 2

Количество 2

nvd логотип

CVE-2025-1475

11 месяцев назад

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if SMS login is enabled.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-hrhc-cx9f-g4q6

11 месяцев назад

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if SMS login is enabled.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-1475

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if SMS login is enabled.

CVSS3: 9.8
1%
Низкий
11 месяцев назад
github логотип
GHSA-hrhc-cx9f-g4q6

The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5. This is due to insufficient verification on the 'user_phone' parameter when logging in. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if SMS login is enabled.

CVSS3: 9.8
1%
Низкий
11 месяцев назад

Уязвимостей на страницу