CVE-2026-15341 (matched: wordpress)

  • Saturday, 15th August, 2026
  • 22:04pm

A critical security flaw, tracked as CVE-2026-15341, affects the User Session Synchronizer plugin for WordPress, impacting all versions up to and including 1.4.0. This vulnerability allows anyone who is not logged into your site to bypass normal login security and take full control of any user account on your WordPress site, including administrator accounts that have complete control over your site's content, settings, and data.

This flaw exists because a core function of the plugin runs on every request to your site without properly validating incoming requests. When specific unregistered plugin settings are used, the security keys the plugin relies on become fully predictable. Attackers can exploit this by sending a specially crafted request that includes a known user's email address, which tricks the plugin into logging the attacker in as that user without needing any passwords, site secrets, or prior access to your account.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341

« Back