plugin

Academist Membership Vulnerabilities

1 known security issue reported for the Academist Membership WordPress plugin. Most recent disclosed Feb 28, 2025.

1 critical

Running Academist Membership on your site? Check whether your installed version is affected.

Scan your site free

Academist Membership <= 1.1.6 - Authentication Bypass via Account Takeover

critical

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attack...

CVSS:
9.8
Affected:
up to 1.1.6
Fixed in:
1.2
Disclosed:
Feb 28, 2025

CVE-2025-1671 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database