cleantalk
Vulnerabilities and Security Researches

MelaPress Login Security, CVE-2025-6895

CVE, Research URL

CVE-2025-6895

Published on
Jul 26, 2025
Research Description
The Melapress Login Security plugin for WordPress is vulnerable to Authentication Bypass due to missing authorization within the get_valid_user_based_on_token() function in versions 2.1.0 to 2.1.1. This makes it possible for unauthenticated attackers who know an arbitrary user meta value to bypass authentication checks and log in as that user.
Affected versions
max 2.2.0.
Status
vulnerable