CVE-2025-2876
08.04.2025, 12:15
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.Enginsight
Vendor | Product | Version |
---|---|---|
melapress | melapress_login_security | 𝑥 < 2.1.1 |
melapress | melapress_login_security | 𝑥 < 2.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References