PT-2025-15420 · Unknown · Melapress Login Security+1

Michelle Porter

·

Published

2025-04-08

·

Updated

2025-07-17

·

CVE-2025-2876

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions: MelaPress Login Security and MelaPress Login Security Premium versions 2.1.0
Description: The issue is related to unauthorized loss of data due to a missing capability check on the monitor admin actions function. This allows unauthenticated attackers to delete any user.
Recommendations: For version 2.1.0, consider disabling the monitor admin actions function until a patch is available to prevent unauthorized user deletion.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-2876

Affected Products

Melapress Login Security
Melapress Login Security Premium