All 3 CVE vulnerabilities found in MelaPress Login Security, with AI-generated Chinese analysis, references, and POCs.
Vendor: Melapress
| CVE ID | Title | CVSS | Severity | Paused |
|---|---|---|---|---|
| CVE-2025-6895 | MelaPress Login Security 2.1.0 - 2.1.1 - Authentication Bypass to Privilege Escalation via get_valid_user_based_on_token Function CWE-288 | 9.8 | Critical | 2025-07-26 |
| CVE-2025-39565 | WordPress MelaPress Login Security plugin <= 2.1.0 - PHP Object Injection Vulnerability CWE-502 | 6.6 | Medium | 2025-04-16 |
| CVE-2024-35650 | WordPress MelaPress Login Security plugin <= 1.3.0 - Remote File Inclusion vulnerability CWE-98 | 4.9 | Medium | 2024-06-10 |
All 3 known CVE vulnerabilities affecting MelaPress Login Security with full Chinese analysis, references, and POCs where available.