Medium severity5.3NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026
CVE-2025-2876
CVE-2025-2876
Description
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:melapress:melapress_login_security:*:*:*:*:free:wordpress:*:*+ 3 more
- cpe:2.3:a:melapress:melapress_login_security:*:*:*:*:free:wordpress:*:*range: <2.1.1
- cpe:2.3:a:melapress:melapress_login_security:*:*:*:*:premium:wordpress:*:*range: <2.1.1
- (no CPE)range: 2.1.0
- (no CPE)range: 2.1.0
<=2.1.0+ 1 more
- (no CPE)range: <=2.1.0
- (no CPE)
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/3267748/nvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/559cbc69-85b6-4bad-9bb2-26d64195ba7envdThird Party Advisory
- melapress.com/wordpress-login-security/releases/nvdRelease Notes
- plugins.trac.wordpress.org/browser/melapress-login-security/trunk/app/modules/temporary-logins/class-temporary-logins.phpnvdProduct
News mentions
0No linked articles in our index yet.