
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-46255 is a Missing Authorization vulnerability in the LoginWP - Pro WordPress plugin developed by Marketing Fire LLC, classified as a Settings Change flaw that allows unauthenticated attackers to modify plugin settings by accessing functionality not properly constrained by access control lists (ACLs). It affects LoginWP - Pro versions up to and including 4.0.8.5, with version 4.0.8.6 containing the fix. The vulnerability was reported by researcher Rafie Muhammad on December 13, 2024, and publicly disclosed by Patchstack on July 22, 2025. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).
The root cause is CWE-862 (Missing Authorization), meaning the plugin fails to verify whether a requesting user has the appropriate permissions before allowing access to settings-modification functionality. This maps to OWASP Top 10 category A1: Broken Access Control. Because no authentication or privilege check is enforced, a remote, unauthenticated attacker can send crafted HTTP requests to the vulnerable plugin endpoint to alter plugin configuration settings. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an unauthenticated remote attacker to arbitrarily modify the LoginWP - Pro plugin's settings on affected WordPress sites, resulting in a high integrity impact with no confidentiality or availability impact. Attackers could manipulate login redirect rules or other authentication-related configurations, potentially redirecting users to malicious pages, bypassing intended access controls, or disrupting the site's authentication workflow. Given that LoginWP - Pro governs login behavior, unauthorized settings changes could facilitate further attacks such as credential harvesting or privilege escalation (Patchstack).
No public proof-of-concept exploit code has been confirmed, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low current probability of exploitation in the wild. However, Patchstack rates this as high priority and notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack). No specific threat actor attribution has been reported.
readme.txt files in the plugin directory (/wp-content/plugins/loginwp-pro/readme.txt).admin-ajax.php or a REST API route.admin-ajax.php or plugin-specific REST API endpoints associated with LoginWP - Pro settings actions from external IP addresses.wp_options table, particularly modifications to redirect URLs or role-based redirect configurations.The vendor has released version 4.0.8.6 of LoginWP - Pro, which patches this vulnerability; all users should update immediately. Patchstack has also issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. If an immediate update is not possible, site administrators should consider temporarily deactivating the plugin or restricting access to WordPress admin endpoints via firewall rules (Patchstack).
Wordfence included CVE-2025-46255 in its weekly WordPress vulnerability report for July 21–27, 2025, highlighting it among notable plugin vulnerabilities (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure and standard vulnerability aggregator coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."