
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25357 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the Ultimate Membership Pro WordPress plugin (slug: indeed-membership-pro) developed by azzaroco. It allows unauthenticated remote attackers to abuse authentication mechanisms and take over user accounts. All plugin versions through 13.7 are affected. The vulnerability was published on March 25, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, ENISA EUVD).
The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the plugin exposes an alternative authentication path or channel that bypasses the primary authentication controls. An unauthenticated network-based attacker can exploit this flaw without any user interaction or prior privileges, though exploitation is rated as high complexity (AC:H). The flaw enables "Authentication Abuse," allowing attackers to authenticate as arbitrary users — including administrators — by leveraging the unprotected alternate channel. No public technical write-up or proof-of-concept code has been disclosed as of the time of reporting (Feedly, Patchstack).
Successful exploitation results in full account takeover, granting attackers unauthorized access to victim user accounts — including potentially administrative accounts — on affected WordPress sites. The CVSS scoring reflects HIGH impact across confidentiality, integrity, and availability, meaning attackers can read sensitive user data, modify account settings and membership records, and potentially disrupt site operations. Privilege escalation to site administrator is a realistic post-exploitation outcome, which could lead to complete WordPress site compromise, malware injection, or data exfiltration (Feedly, ENISA EUVD).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, ENISA EUVD).
No official patch has been confirmed in the available data at the time of reporting. Site owners running Ultimate Membership Pro version 13.7 or earlier should take the following immediate steps:
(Feedly, Patchstack)
Wordfence included CVE-2026-25357 in its weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as a notable authentication bypass issue in the Ultimate Membership Pro plugin (Wordfence). Patchstack, which assigned and disclosed the CVE, flagged it as an account takeover vulnerability. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."