WordPress Login Me Now Plugin Authentication Bypass Vulnerability

Vulnerability

An authentication bypass vulnerability has been identified in the Login Me Now plugin for WordPress, affecting versions through 1.7.2. The issue arises from insecure authentication that relies on an arbitrary transient name in the 'AutoLogin::listen()' function. This vulnerability allows unauthenticated attackers to log in as existing users, including administrators, on the site. It is important to note that exploitation requires a transient name and value from another software, meaning the plugin is not inherently vulnerable on its own.

Impact

Exploitation of this vulnerability allows for authentication bypass, enabling unauthorized users to log in as existing users, potentially including administrators.

Reproduction

To reproduce this vulnerability, an attacker must send a request to the WordPress site with a transient name and value obtained from another software, targeting the 'lmn' parameter. The 'AutoLogin::listen()' function will process the request, bypassing authentication and logging in the user associated with the transient value.

Remediation

Users are advised to update the Login Me Now plugin to version 1.7.3 or a newer patched version.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.2
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.