CVE-2025-2876
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 8, 2025
CWE ID 862
Summary
CVE-2025-2876 is a vulnerability affecting the MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress. The issue lies in the 'monitor_admin_actions' function, which lacks proper capability checks in version 2.1.0. Consequently, unauthenticated attackers can exploit this flaw to delete any user data, posing a significant risk to website security and confidentiality. This vulnerability underscores the importance of regularly updating plugins and implementing robust security measures to protect against potential data loss.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.