Authentication Bypass Vulnerability in Login Me Now Plugin for WordPress
CVE-2025-1717

8.1HIGH

Key Information:

Vendor
Pluginly
Status
1 Click Passwordless Login, Temporary Login, Social Login & User Switching – Login Me Now
Vendor
CVE Published:
27 February 2025

Summary

The Login Me Now plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass authentication, enabling them to log in as any existing user, including administrators. This issue arises from insecure authentication mechanisms that rely on arbitrary transient names within the 'AutoLogin::listen()' function. Although the plugin is not inherently vulnerable, its configuration can expose it to risk if transient names and values from other software are used.

Affected Version(s)

1 click passwordless login, temporary login, social login & user switching – Login Me Now * <= 1.7.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

István Márton
.