nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-10648 CVE-2025-10648
MEDIUM
Login with YourMembership - YM SSO Login <= 1.1.7 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'moym_display_test_attributes'
Record summary
CVE-2025-10648 has a selected CVSS score of 5.3 (medium).
Description
The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'moym_display_test_attributes' function in all versions up to, and including, 1.1.7. This makes it possible for unauthenticated attackers to read the profile data of the latest SSO login.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Login with YourMembership – YM SSO LoginBrowse cyberlord92 / Login with YourMembership – YM SSO LoginDefault status: unaffected | CVE List | Through 1.1.7 | affected |
References
4plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/browser/login-with-yourmembership/trunk/class-moym-sso.php plugins.trac.wordpress.org
https://plugins.trac.wordpress.org/changeset/3389623 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/1bb25412-8f63-4a9d-84bd-44fac59c6eed?source=cve