CVE-2025-6895: MelaPress Login Security 2.1.0 - 2.1.1 - Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6895?
CVE-2025-6895 has been classified as a high severity vulnerability due to its potential for authentication bypass.
How do I fix CVE-2025-6895?
To fix CVE-2025-6895, update the Melapress Login Security plugin to version 2.1.2 or later.
Who is affected by CVE-2025-6895?
CVE-2025-6895 affects users of the Melapress Login Security plugin for WordPress in versions 2.1.0 to 2.1.1.
What type of vulnerability is CVE-2025-6895?
CVE-2025-6895 is an authentication bypass vulnerability that allows unauthenticated attackers to exploit the plugin.
What can attackers do with CVE-2025-6895?
Attackers exploiting CVE-2025-6895 can gain unauthorized access by bypassing user authentication mechanisms in the plugin.