A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0. The flawed code runs automatically on every page load of sites using the plugin, and fails to properly verify that incoming requests to the plugin's sync feature are legitimate.
This gap allows unauthenticated attackers (people who are not logged into your site at all) to send specially crafted requests to your website. If an attacker knows or can guess the email address of any user on your site, including administrators, they can exploit this flaw to gain full, unrestricted access to that user's account without needing a password or any other private site credentials.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341