PT-2025-30019 · WordPress · Loginpress Pro
Friderika Baranyai
·
Published
2025-07-18
·
Updated
2025-07-18
·
CVE-2025-7444
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LoginPress Pro versions prior to 5.0.1
Description
The LoginPress Pro plugin for WordPress is susceptible to authentication bypass in all versions up to and including 5.0.1. This issue stems from inadequate verification of the user returned by the social login token. This allows unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the email address and the user does not already have an account for the service returning the token.
Recommendations
Update LoginPress Pro to version 5.0.1 or later.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Loginpress Pro