Vulnerabilities (CVE)

Filtered by vendor Melapress Subscribe
Filtered by product Melapress Login Security
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-39565 1 Melapress 1 Melapress Login Security 2025-07-17 N/A 6.6 MEDIUM
Deserialization of Untrusted Data vulnerability in Melapress MelaPress Login Security allows Object Injection. This issue affects MelaPress Login Security: from n/a through 2.1.0.
CVE-2025-2876 1 Melapress 1 Melapress Login Security 2025-07-17 N/A 5.3 MEDIUM
The MelaPress Login Security and MelaPress Login Security Premium plugins for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'monitor_admin_actions' function in version 2.1.0. This makes it possible for unauthenticated attackers to delete any user.
CVE-2024-35650 1 Melapress 1 Melapress Login Security 2024-11-21 N/A 4.9 MEDIUM
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Melapress MelaPress Login Security allows PHP Remote File Inclusion.This issue affects MelaPress Login Security: from n/a through 1.3.0.