MelaPress Login Security and MelaPress Login Security Premium 2.1.0 - Missing Authorization to Unauthenticated Arbitrary User Deletion
mediumThe MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
- CVSS:
- 5.3
- Affected:
- 2.1.0 – 2.1.0
- Fixed in:
- 2.1.1
- Disclosed:
- Apr 7, 2025