Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7.
Subscriptions
No data.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass Using an Alternate Path or Channel vulnerability in azzaroco Ultimate Membership Pro indeed-membership-pro allows Authentication Abuse.This issue affects Ultimate Membership Pro: from n/a through <= 13.7. | |
| Title | WordPress Ultimate Membership Pro plugin <= 13.7 - Account Takeover vulnerability | |
| Weaknesses | CWE-288 | |
| References |
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-03-25T16:14:44.726Z
Reserved: 2026-02-02T12:52:48.541Z
Link: CVE-2026-25357
No data.
Status : Received
Published: 2026-03-25T17:16:46.743
Modified: 2026-03-25T17:16:46.743
Link: CVE-2026-25357
No data.
OpenCVE Enrichment
Updated: 2026-03-25T21:44:55Z
Weaknesses