plugin

Melapress Login Security Vulnerabilities

4 known security issues reported for the Melapress Login Security WordPress plugin. Most recent disclosed Jul 25, 2025.

1 critical 1 high 2 medium

Running Melapress Login Security on your site? Check whether your installed version is affected.

Scan your site free

MelaPress Login Security 2.1.0 - 2.1.1 - Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function

critical

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks...

CVSS:
9.8
Affected:
2.1.0 – 2.1.1
Fixed in:
2.2.0
Disclosed:
Jul 25, 2025

CVE-2025-6895 on NVD →

MelaPress Login Security <= 2.1.0 - Authenticated (Administrator+) PHP Object Injection

high

The MelaPress Login Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in...

CVSS:
7.2
Affected:
up to 2.1.0
Fixed in:
2.1.1
Disclosed:
Apr 16, 2025

CVE-2025-39565 on NVD →

MelaPress Login Security and MelaPress Login Security Premium 2.1.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion

medium

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.

CVSS:
5.3
Affected:
2.1.0 – 2.1.0
Fixed in:
2.1.1
Disclosed:
Apr 7, 2025

CVE-2025-2876 on NVD →

MelaPress Login Security <= 1.3.0 - Authenticated (Admin+) Remote File Inclusion

medium

The MelaPress Login Security plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.3.0 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files hosted on remote servers, al...

CVSS:
6.6
Affected:
up to 1.3.0
Fixed in:
1.3.1
Disclosed:
Jun 3, 2024

CVE-2024-35650 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database