9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.
Basic Information
ID
CVE-2025-6895
Source
Wordfence
Published
Jul 26, 2025 at 04:25
Modified
Jul 28, 2025 at 18:33
Affected Product
Vendor
melapress
Product
Melapress Login Security
Version
2.1.0
Affected Versions
melapress Melapress Login Security 2.1.0
CWE Classification
References
- www.wordfence.com /threat-intel/vulnerabilities/id/6f65d5c4-6f53-4836-9130-c9f4ed3be893
- wordpress.org /plugins/melapress-login-security/
- plugins.trac.wordpress.org /browser/melapress-login-security/tags/2.1.1/app/class-melapress-login-security.php
- plugins.trac.wordpress.org /browser/melapress-login-security/tags/2.1.1/app/modules/temporary-logins/class-temporary-logins.php
- plugins.trac.wordpress.org /changeset/3328137