Логотип exploitDog
bind:CVE-2025-6895
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-6895

Количество 2

Количество 2

nvd логотип

CVE-2025-6895

7 месяцев назад

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-rgqx-f26c-5v58

7 месяцев назад

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-6895

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

CVSS3: 9.8
1%
Низкий
7 месяцев назад
github логотип
GHSA-rgqx-f26c-5v58

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

CVSS3: 9.8
1%
Низкий
7 месяцев назад

Уязвимостей на страницу