PT-2025-9165 · WordPress · Alloggio Membership

Tonn

·

Published

2025-03-01

·

Updated

2025-03-07

·

CVE-2025-1638

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Alloggio Membership plugin for WordPress version 1.0.2 and earlier
Description The issue is related to the plugin not properly validating a user's identity through the alloggio membership init rest api facebook login and alloggio membership init rest api google login functions. This allows unauthenticated attackers to log in as any user, including administrators, without knowing a password.
Recommendations For versions up to and including 1.0.2, update to a version that fixes the authentication bypass issue. As a temporary workaround, consider disabling the alloggio membership init rest api facebook login and alloggio membership init rest api google login functions until a patch is available.

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1638

Affected Products

Alloggio Membership