Description

The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.

INFO

Published Date :

2025-04-08T11:11:31.603Z

Last Modified :

2025-04-08T12:59:23.581Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-2876 vulnerability.

Vendors Products
Melapress
  • Melapress Login Security
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact