PT-2025-8922 · WordPress · Login Me Now

István Márton

·

Published

2025-02-27

·

Updated

2025-02-28

·

CVE-2025-1717

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Login Me Now plugin for WordPress versions up to, and including, 1.7.2
Description The issue is related to insecure authentication based on an arbitrary transient name in the AutoLogin::listen() function, allowing unauthenticated attackers to log in as an existing user, including administrators, by utilizing a transient name and value from another software.
Recommendations For versions up to, and including, 1.7.2, consider disabling the AutoLogin::listen() function until a patch is available to prevent exploitation. Restrict access to sensitive areas of the site to minimize the risk of unauthorized login.

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1717

Affected Products

Login Me Now