CVE 9.8 CRITICAL

MelaPress Login Security 2.1.0 – 2.1.1 – Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function_CVE-2025-6895

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.

Basic Information

ID CVE-2025-6895
Source Wordfence
Published Jul 26, 2025 at 04:25
Modified Jul 28, 2025 at 18:33

Affected Product

Vendor melapress
Product Melapress Login Security
Version 2.1.0
Affected Versions melapress Melapress Login Security 2.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.