MelaPress Login Security 2.1.0 - 2.1.1 - Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function
critical
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks...
- CVSS:
- 9.8
- Affected:
- 2.1.0 – 2.1.1
- Fixed in:
- 2.2.0
- Disclosed:
- Jul 25, 2025
CVE-2025-6895 on NVD →
MelaPress Login Security <= 2.1.0 - Authenticated (Administrator+) PHP Object Injection
high
The MelaPress Login Security plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.1.0 via deserialization of untrusted input. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP Object. No known POP chain is present in...
- CVSS:
- 7.2
- Affected:
- up to 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 16, 2025
CVE-2025-39565 on NVD →
MelaPress Login Security and MelaPress Login Security Premium 2.1.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion
medium
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
- CVSS:
- 5.3
- Affected:
- 2.1.0 – 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 7, 2025
CVE-2025-2876 on NVD →
MelaPress Login Security <= 1.3.0 - Authenticated (Admin+) Remote File Inclusion
medium
The MelaPress Login Security plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 1.3.0 via the 'tab' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files hosted on remote servers, al...
- CVSS:
- 6.6
- Affected:
- up to 1.3.0
- Fixed in:
- 1.3.1
- Disclosed:
- Jun 3, 2024
CVE-2024-35650 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database