๐Ÿ” CVE Alert

CVE-2025-1671

CRITICAL 9.8

Academist Membership <= 1.1.6 - Authentication Bypass via Account Takeover

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Academist Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.1.6. This is due to the academist_membership_check_facebook_user() function not properly verifying a user's identity prior to authenticating them. This makes it possible for unauthenticated attackers to log in as any user, including site administrators.

CWE CWE-288
Vendor elated-themes
Product academist membership
Published Mar 1, 2025
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for elated-themes academist membership

Be the first to know when new critical vulnerabilities affecting elated-themes academist membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Elated-Themes / Academist Membership
0 โ‰ค 1.1.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/911a9550-1f62-4f28-9d8c-00d9769949c9?source=cve themeforest.net: https://themeforest.net/item/academist-a-modern-learning-management-system-and-education-theme/22376830

Credits

Tonn