CVE-2026-15341 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 04:04am

A critical security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, impacting all versions up to and including 1.4.0. This flaw allows unauthenticated attackers to bypass normal login security measures to take over any user account on a WordPress site, including high-level administrator accounts.

The vulnerability exists because the plugin fails to properly validate specific incoming request parameters. This lets attackers send a deliberately modified request that tricks the site into granting them full authenticated access to any targeted user account. No knowledge of the site’s passwords, private secrets, or existing login credentials is required to exploit this flaw.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341

« Back