The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authentication based on an arbitrary transient name in the 'AutoLogin::listen()' function. This makes it possible for unauthenticated attackers to log in an existing user on the site, even an administrator. Note: this vulnerability requires using a transient name and value from another software, so the plugin is not inherently vulnerable on it's own.
History

Tue, 11 Mar 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Pluginly
Pluginly login Me Now
Weaknesses CWE-306
CPEs cpe:2.3:a:pluginly:login_me_now:*:*:*:*:*:wordpress:*:*
Vendors & Products Pluginly
Pluginly login Me Now

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Feb 2025 07:30:00 +0000

Type Values Removed Values Added
Description The Login Me Now plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.7.2. This is due to insecure authentication based on an arbitrary transient name in the 'AutoLogin::listen()' function. This makes it possible for unauthenticated attackers to log in an existing user on the site, even an administrator. Note: this vulnerability requires using a transient name and value from another software, so the plugin is not inherently vulnerable on it's own.
Title Login Me Now <= 1.7.2 - Authentication Bypass
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-02-27T07:23:13.273Z

Updated: 2025-02-27T14:38:26.954Z

Reserved: 2025-02-26T15:43:02.736Z

Link: CVE-2025-1717

cve-icon Vulnrichment

Updated: 2025-02-27T14:38:22.248Z

cve-icon NVD

Status : Analyzed

Published: 2025-02-27T08:15:31.130

Modified: 2025-03-11T16:12:42.783

Link: CVE-2025-1717

cve-icon Redhat

No data.