Authentication Bypass Vulnerability in Login Me Now Plugin for WordPress
CVE-2025-1717
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 February 2025
What is CVE-2025-1717?
The Login Me Now plugin for WordPress has a vulnerability that allows unauthenticated attackers to bypass authentication, enabling them to log in as any existing user, including administrators. This issue arises from insecure authentication mechanisms that rely on arbitrary transient names within the 'AutoLogin::listen()' function. Although the plugin is not inherently vulnerable, its configuration can expose it to risk if transient names and values from other software are used.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
1 click passwordless login, temporary login, social login & user switching – Login Me Now * <= 1.7.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved