PT-2025-8922 · WordPress · Login Me Now
István Márton
·
Published
2025-02-27
·
Updated
2025-02-28
·
CVE-2025-1717
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Login Me Now plugin for WordPress versions up to, and including, 1.7.2
Description
The issue is related to insecure authentication based on an arbitrary transient name in the
AutoLogin::listen() function, allowing unauthenticated attackers to log in as an existing user, including administrators, by utilizing a transient name and value from another software.Recommendations
For versions up to, and including, 1.7.2, consider disabling the
AutoLogin::listen() function until a patch is available to prevent exploitation. Restrict access to sensitive areas of the site to minimize the risk of unauthorized login.Fix
Missing Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Login Me Now