Login with NEAR <= 0.3.3 - Authentication Bypass via 'account' Parameter
highThe Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplied `account` POST parameter and issues a...
- CVSS:
- 8.1
- Affected:
- up to 0.3.3
- Fix:
- No patched version reported
- Disclosed:
- May 26, 2026