A security flaw tracked as CVE-2026-15341 has been found in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0.
This is an authentication bypass vulnerability, meaning unauthenticated attackers can take full control of any user account on a WordPress site running the affected plugin, including administrator accounts, without needing any valid login credentials or access to private site information.
If an attacker gains administrator access to your site, they can make unauthorized changes to your content, access sensitive data stored in your WordPress backend, or add harmful content that could negatively impact your visitors and your site's reputation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341