CVE-2025-1564

CRITICAL

SetSail Membership <1.0.3 - Auth Bypass

Title source: llm
STIX 2.1

Description

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account.

Scores

CVSS v3 9.8
EPSS 0.0052
EPSS Percentile 39.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (1)
Select-Themes/SetSail Membership < 1.0.3
Published Mar 01, 2025
Tracked Since Feb 18, 2026