PT-2025-9166 · WordPress · Academist Membership

Tonn

·

Published

2025-03-01

·

Updated

2025-03-07

·

CVE-2025-1671

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Academist Membership plugin for WordPress versions prior to 1.1.7
Description The issue is related to privilege escalation due to the academist membership check facebook user() function not properly verifying a user's identity before authentication. This allows unauthenticated attackers to log in as any user, including site administrators.
Recommendations For versions up to and including 1.1.6, update to a version newer than 1.1.6 to resolve the issue. As a temporary workaround, consider disabling the academist membership check facebook user() function until a patch is available.

Fix

LPE

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1671

Affected Products

Academist Membership