CVE-2025-58595: WordPress All In One Login plugin <= 2.0.8 - Bypass Vulnerability vulnerability
Published Nov 6, 2025
·Updated
Authentication Bypass by Spoofing vulnerability in Saad Iqbal All In One Login change-wp-admin-login allows Identity Spoofing.This issue affects All In One Login: from n/a through <= 2.0.8.
Affected Software
2 affected components
Saad Iqbal All In One Login<=2.0.8
WordPress All In One Login<=2.0.8
Event History
Nov 6, 2025
CVE Published
via MITRE·03:54 PM
Data Sourced
via MITRE·03:54 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-58595?
CVE-2025-58595 has been identified as a critical vulnerability due to its potential for authentication bypass.
2
How do I fix CVE-2025-58595?
To fix CVE-2025-58595, update the All In One Login plugin to version 2.0.9 or later.
3
Who is affected by CVE-2025-58595?
CVE-2025-58595 affects users of the All In One Login plugin for WordPress versions up to and including 2.0.8.
4
What type of vulnerability is CVE-2025-58595?
CVE-2025-58595 is categorized as an authentication bypass by spoofing vulnerability.
5
Can CVE-2025-58595 lead to unauthorized access?
Yes, CVE-2025-58595 can allow attackers to gain unauthorized access to accounts by exploiting the authentication flaw.