CVE-2025-1564

The SetSail Membership plugin for WordPress is vulnerable to in all versions up to, and including, 1.0.3. This is due to the plugin not properly verifying a users identity through the social login. This makes it possible for unauthenticated attackers to log in as any user, including administrators and take over access to their account.
Configurations

No configuration.

History

01 Mar 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-01 08:15

Updated : 2025-03-01 08:15


NVD link : CVE-2025-1564

Mitre link : CVE-2025-1564

CVE.ORG link : CVE-2025-1564


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel