CVE-2025-2876
MEDIUMMelaPress Login Security < 2.1.1 - Unauthenticated Arbitrary User Deletion via Missing Capability Check
Title source: llmDescription
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
References (4)
Core 4
Core References
Release Notes
https://melapress.com/wordpress-login-security/releases/
Scores
CVSS v3
5.3
EPSS
0.0031
EPSS Percentile
22.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (1)
melapress/melapress_login_security
< 2.1.1 (2 CPE variants)
Published
Apr 08, 2025
Tracked Since
Feb 18, 2026