CVE-2025-46255
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-46255 is a Missing Authorization vulnerability in the LoginWP - Pro WordPress plugin developed by Marketing Fire LLC, classified as a Settings Change flaw that allows unauthenticated attackers to modify plugin settings by accessing functionality not properly constrained by access control lists (ACLs). It affects LoginWP - Pro versions up to and including 4.0.8.5, with version 4.0.8.6 containing the fix. The vulnerability was reported by researcher Rafie Muhammad on December 13, 2024, and publicly disclosed by Patchstack on July 22, 2025. It carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack (Patchstack).

Technical details

The root cause is CWE-862 (Missing Authorization), meaning the plugin fails to verify whether a requesting user has the appropriate permissions before allowing access to settings-modification functionality. This maps to OWASP Top 10 category A1: Broken Access Control. Because no authentication or privilege check is enforced, a remote, unauthenticated attacker can send crafted HTTP requests to the vulnerable plugin endpoint to alter plugin configuration settings. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an unauthenticated remote attacker to arbitrarily modify the LoginWP - Pro plugin's settings on affected WordPress sites, resulting in a high integrity impact with no confidentiality or availability impact. Attackers could manipulate login redirect rules or other authentication-related configurations, potentially redirecting users to malicious pages, bypassing intended access controls, or disrupting the site's authentication workflow. Given that LoginWP - Pro governs login behavior, unauthorized settings changes could facilitate further attacks such as credential harvesting or privilege escalation (Patchstack).

Exploitability

No public proof-of-concept exploit code has been confirmed, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.016% (0.000160), indicating a low current probability of exploitation in the wild. However, Patchstack rates this as high priority and notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack). No specific threat actor attribution has been reported.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the LoginWP - Pro plugin (versions ≤ 4.0.8.5) using tools like WPScan, Shodan, or by checking publicly accessible readme.txt files in the plugin directory (/wp-content/plugins/loginwp-pro/readme.txt).
  2. Identify vulnerable endpoint: Locate the plugin's settings-handling endpoint or admin-ajax action that lacks authorization checks, typically accessible via WordPress's admin-ajax.php or a REST API route.
  3. Craft malicious request: Send an unauthenticated HTTP POST request to the identified endpoint with parameters designed to modify plugin settings (e.g., login redirect URLs or role-based redirect rules).
  4. Achieve objective: The plugin processes the request without verifying user permissions, applying the attacker-supplied settings — for example, redirecting all users upon login to an attacker-controlled URL for credential harvesting or phishing (Patchstack).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to WordPress admin-ajax.php or plugin-specific REST API endpoints associated with LoginWP - Pro settings actions from external IP addresses.
  • Logs: WordPress access logs showing POST requests to settings-related endpoints without a valid authenticated session cookie; repeated requests from the same IP targeting plugin configuration endpoints.
  • File System / Database: Unexpected changes to LoginWP - Pro plugin settings stored in the WordPress wp_options table, particularly modifications to redirect URLs or role-based redirect configurations.
  • Behavior: Users being redirected to unexpected or external URLs upon login, which may indicate that redirect settings have been tampered with (Patchstack).

Mitigation and workarounds

The vendor has released version 4.0.8.6 of LoginWP - Pro, which patches this vulnerability; all users should update immediately. Patchstack has also issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until the plugin is updated. If an immediate update is not possible, site administrators should consider temporarily deactivating the plugin or restricting access to WordPress admin endpoints via firewall rules (Patchstack).

Community reactions

Wordfence included CVE-2025-46255 in its weekly WordPress vulnerability report for July 21–27, 2025, highlighting it among notable plugin vulnerabilities (Wordfence Blog). No significant broader media coverage or notable researcher commentary beyond the Patchstack disclosure and standard vulnerability aggregator coverage has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-15239NONEN/A
  • simple-cloudflare-turnstile
NoYesAug 07, 2026
CVE-2026-15211NONEN/A
  • subscriptions-for-woocommerce
NoYesAug 07, 2026
CVE-2026-15148NONEN/A
  • wp-events-manager
NoYesAug 07, 2026
CVE-2026-16265NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026
CVE-2026-16263NONEN/A
  • wp-google-map-plugin
NoYesAug 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management