CVE-2025-46255

7.5

Marketing Fire LLC · LoginWP - Pro

A missing authorization vulnerability in the LoginWP - Pro WordPress plugin allows unauthenticated attackers to access and modify restricted functionality.

Executive summary

A critical missing authorization flaw in the LoginWP - Pro plugin exposes administrative settings to unauthenticated remote attackers.

Vulnerability

This vulnerability is a missing authorization flaw (CWE-862) that allows an unauthenticated user to access and manipulate plugin settings, as the software fails to properly verify the requester's identity or permissions before executing sensitive functions.

Business impact

The ability for an unauthenticated attacker to modify plugin settings poses a significant risk to site integrity and security configurations. Successful exploitation could lead to unauthorized changes in authentication workflows or system behavior, potentially resulting in complete site takeover or the bypass of security controls. Given the CVSS score of 7.5, this high severity vulnerability necessitates immediate attention to prevent potential service disruption or malicious configuration changes.

Remediation

Immediate Action: Update the LoginWP - Pro WordPress plugin to version 4.0.8.6 or later immediately.

Proactive Monitoring: Review web server access logs for anomalous requests targeting plugin configuration endpoints or unexpected administrative modifications.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block unauthorized requests to the plugin's administrative settings pages until the update is applied.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The vulnerability represents a significant security oversight that facilitates unauthorized control over plugin functionality. Administrators must prioritize the application of the vendor-provided patch to version 4.0.8.6 to eliminate the authorization bypass vector. Failure to update leaves the site exposed to potential configuration manipulation by remote, unauthenticated actors.

More Marketing Fire LLC CVEs

Sources

Originally found and disclosed by Rafie Muhammad | Patchstack Threat Intelligence, per the CVE Program record.