
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13539 is an authentication bypass vulnerability in the FindAll Membership plugin for WordPress, affecting all versions up to and including 1.0.4. The flaw allows unauthenticated attackers to log in as administrative users by exploiting improper session handling after social login verification via Facebook and Google. It was published on November 27, 2025, and assigned by Wordfence. It carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel). The plugin's findall_membership_check_facebook_user and findall_membership_check_google_user functions verify social login credentials but fail to properly bind the verified identity to the resulting WordPress session, allowing an attacker to decouple the verification step from the login step. An attacker can exploit this by first creating a temporary account (enabled by default via the plugin's temp user functionality) and then supplying a target administrative user's email address to hijack that admin session without valid credentials. No authentication or user interaction is required (Wordfence, ENISA EUVD).
Successful exploitation grants an unauthenticated attacker full administrative control over the affected WordPress site, resulting in high confidentiality, integrity, and availability impact. An attacker could steal sensitive user and site data, modify or delete site content, install malicious plugins or backdoors, and use the compromised site as a pivot point for further attacks. The default enablement of the temp user registration feature means the precondition of having an existing account is trivially satisfied on most affected installations (Wordfence, ENISA EUVD).
/wp-content/plugins/findall-membership/./?author=1), exposed user data, or other OSINT techniques.wp-login.php access logs) showing successful admin logins from unfamiliar IP addresses or at unusual times; log entries showing rapid account creation via temp user functionality followed shortly by admin-level login events.findall_membership_check_facebook_user or findall_membership_check_google_user) originating from unknown or suspicious IP addresses.wp-content/ directories not authorized by site administrators; presence of web shells or obfuscated PHP scripts.The primary remediation is to update the FindAll Membership plugin to a version beyond 1.0.4 that addresses this vulnerability. If no patched version is immediately available, the plugin should be disabled entirely to eliminate the attack surface. Additionally, administrators should audit all user accounts (especially temporary and administrative accounts), review recent login and admin activity logs for signs of unauthorized access, and consider implementing multi-factor authentication for WordPress admin accounts. Disabling the temp user registration feature, if not required, further reduces the preconditions for exploitation (Wordfence, ENISA EUVD).
Wordfence disclosed the vulnerability and included it in their weekly WordPress vulnerability report for the week of November 24–30, 2025, flagging it as a critical authentication bypass (Wordfence Blog). CISA referenced the vulnerability in their weekly vulnerability bulletin (SB25-335) (CISA Bulletin). No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregator reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."