1 results (0.002 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

28 Feb 2025 — The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators. • https://themeforest.net/item/academist-a-modern-learning-management-system-and-education-theme/22376830 • CWE-288: Authentication Bypass Using an Alternate Path or Channel •