Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5896 | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators. |
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 01 Mar 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators. | |
| Title | Academist Membership <= 1.1.6 - Authentication Bypass via Account Takeover | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:06:54.805Z
Reserved: 2025-02-24T21:51:36.610Z
Link: CVE-2025-1671
Updated: 2025-03-03T20:55:29.221Z
Status : Deferred
Published: 2025-03-01T08:15:34.320
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1671
No data.
OpenCVE Enrichment
Updated: 2026-04-21T22:15:45Z
EUVD