CVE-2025-2876
5.3
MediumCVE-2025-2876
•
security@wordfence.com
•
Awaiting Analysis
Description
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
Exploits
No known exploits found for this CVE.
Search Exploit-DBReferences
security@wordfence.com
https://melapress.com/wordpress-login-security/releases/security@wordfence.com
https://plugins.trac.wordpress.org/browser/melapress-login-security/trunk/app/modules/temporary-logins/class-temporary-logins.php#L71security@wordfence.com
https://plugins.trac.wordpress.org/changeset/3267748/