CVE-2025-6895

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/07/2025
Last modified:
29/07/2025

Description

The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.