CVE-2026-25357
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-25357 is an Authentication Bypass Using an Alternate Path or Channel vulnerability (CWE-288) in the Ultimate Membership Pro WordPress plugin (slug: indeed-membership-pro) developed by azzaroco. It allows unauthenticated remote attackers to abuse authentication mechanisms and take over user accounts. All plugin versions through 13.7 are affected. The vulnerability was published on March 25, 2026, and was assigned by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, ENISA EUVD).

Technical details

The vulnerability is classified under CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the plugin exposes an alternative authentication path or channel that bypasses the primary authentication controls. An unauthenticated network-based attacker can exploit this flaw without any user interaction or prior privileges, though exploitation is rated as high complexity (AC:H). The flaw enables "Authentication Abuse," allowing attackers to authenticate as arbitrary users — including administrators — by leveraging the unprotected alternate channel. No public technical write-up or proof-of-concept code has been disclosed as of the time of reporting (Feedly, Patchstack).

Impact

Successful exploitation results in full account takeover, granting attackers unauthorized access to victim user accounts — including potentially administrative accounts — on affected WordPress sites. The CVSS scoring reflects HIGH impact across confidentiality, integrity, and availability, meaning attackers can read sensitive user data, modify account settings and membership records, and potentially disrupt site operations. Privilege escalation to site administrator is a realistic post-exploitation outcome, which could lead to complete WordPress site compromise, malware injection, or data exfiltration (Feedly, ENISA EUVD).

Exploitability

As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.024%, indicating a currently low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly, ENISA EUVD).

Mitigation and workarounds

No official patch has been confirmed in the available data at the time of reporting. Site owners running Ultimate Membership Pro version 13.7 or earlier should take the following immediate steps:

  • Monitor authentication logs for unusual login activity, unexpected account access, or privilege changes.
  • Implement multi-factor authentication (MFA) for all user accounts, especially administrators.
  • Apply IP allowlisting for administrative login endpoints where feasible.
  • Enhance logging of all authentication attempts and review for anomalies.
  • Contact azzaroco or Patchstack for patch availability and apply any released update immediately.
  • Consider temporarily disabling the plugin if no patch is available and the risk is unacceptable.

(Feedly, Patchstack)

Community reactions

Wordfence included CVE-2026-25357 in its weekly WordPress vulnerability report covering March 23–29, 2026, highlighting it as a notable authentication bypass issue in the Ultimate Membership Pro plugin (Wordfence). Patchstack, which assigned and disclosed the CVE, flagged it as an account takeover vulnerability. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78570CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78568CRITICAL9.8
  • totaldonations
NoNoAug 25, 2026
CVE-2026-78572HIGH8.1
  • kalles-addons
NoNoAug 25, 2026
CVE-2026-78576HIGH7.5
  • readabler
NoYesAug 25, 2026
CVE-2026-76128MEDIUM6.4
  • ecommerce-product-catalog
NoYesAug 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management