CVE-2025-13539
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13539 is an authentication bypass vulnerability in the FindAll Membership plugin for WordPress, affecting all versions up to and including 1.0.4. The flaw allows unauthenticated attackers to log in as administrative users by exploiting improper session handling after social login verification via Facebook and Google. It was published on November 27, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The plugin's findall_membership_check_facebook_user and findall_membership_check_google_user functions verify social login credentials but fail to properly bind the verified identity to the resulting WordPress session, allowing an attacker to decouple the verification step from the login step. An attacker can exploit this by first creating a temporary account (enabled by default via the plugin's temp user functionality) and then supplying a target administrative user's email address to hijack that admin session without valid credentials. No authentication or user interaction is required (Wordfence, ENISA EUVD).

Impact

Successful exploitation grants an unauthenticated attacker full administrative control over the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker could steal sensitive user and site data, modify or delete site content, install malicious plugins or backdoors, and use the compromised site as a pivot point for further attacks. The default enablement of the temp user registration feature means the precondition of having an existing account is trivially satisfied on most affected installations (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the FindAll Membership plugin (version ≤ 1.0.4) using tools like WPScan or by checking publicly accessible plugin metadata at /wp-content/plugins/findall-membership/.
  2. Create a temporary account: Use the plugin's default temp user registration functionality to create a low-privilege or temporary account on the target site, satisfying the precondition of having an existing account.
  3. Obtain target admin email: Enumerate the administrative user's email address via WordPress author enumeration (e.g., /?author=1), exposed user data, or other OSINT techniques.
  4. Trigger the social login flow: Initiate the Facebook or Google social login process through the plugin's authentication endpoint, supplying the administrative user's email address during the verification step.
  5. Bypass session binding: Exploit the improper session handling — the plugin logs in the user associated with the supplied email without properly validating that the verified social identity matches that account, resulting in an authenticated session as the administrator.
  6. Achieve administrative access: Use the resulting WordPress admin session to take full control of the site, install backdoors, exfiltrate data, or perform other malicious actions (Wordfence, ENISA EUVD).

Indicators of compromise

  • Logs: WordPress authentication logs (wp-login.php access logs) showing successful admin logins from unfamiliar IP addresses or at unusual times; log entries showing rapid account creation via temp user functionality followed shortly by admin-level login events.
  • Network: Unexpected POST requests to social login endpoints (e.g., plugin-specific AJAX handlers for findall_membership_check_facebook_user or findall_membership_check_google_user) originating from unknown or suspicious IP addresses.
  • File System: Newly installed plugins, themes, or PHP files in wp-content/ directories not authorized by site administrators; presence of web shells or obfuscated PHP scripts.
  • WordPress Admin: Unexpected new administrator accounts or changes to existing admin account details; unfamiliar plugins activated or site options modified in the WordPress dashboard.

Mitigation and workarounds

The primary remediation is to update the FindAll Membership plugin to a version beyond 1.0.4 that addresses this vulnerability. If no patched version is immediately available, the plugin should be disabled entirely to eliminate the attack surface. Additionally, administrators should audit all user accounts (especially temporary and administrative accounts), review recent login and admin activity logs for signs of unauthorized access, and consider implementing multi-factor authentication for WordPress admin accounts. Disabling the temp user registration feature, if not required, further reduces the preconditions for exploitation (Wordfence, ENISA EUVD).

Community reactions

Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for the week of November 24–30, 2025, flagging it as a critical authentication bypass (Wordfence Blog). CISA referenced the vulnerability in their weekly vulnerability bulletin (SB25-335) (CISA Bulletin). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator reporting.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-13147CRITICAL9.1
  • kirki
NoYesJul 20, 2026
CVE-2026-9833HIGH7.1
  • tag-groups
NoYesJul 20, 2026
CVE-2026-13432MEDIUM5.4
  • image-sizes
NoYesJul 20, 2026
CVE-2026-13156MEDIUM5.4
  • mailersend-official-smtp-integration
NoYesJul 20, 2026
CVE-2026-8825MEDIUM4.9
  • elementor
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management