A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions up to and including 1.4.0. This flaw allows people who are not logged into your site to take over any user account on the site, including administrator accounts, without needing to know any passwords or access your site’s private secrets.
If an attacker successfully exploits this flaw, they gain full access to the compromised account. For administrator accounts, this gives them the ability to make any changes to your site, access all your stored site data, and take actions that could disrupt your business or harm your site visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341