A security vulnerability tracked as CVE-2026-15341 has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions of the plugin up to and including 1.4.0. This flaw allows unauthenticated visitors (people who are not logged into your site) to take full control of any user account on your WordPress site, including administrator accounts, if they know the email address associated with that account. The issue exists because the plugin does not properly verify that incoming requests to its session synchronization feature are legitimate. Attackers can send a specially crafted request to your site that tricks the plugin into logging them in as the user whose email address they included in the request, with no need for passwords, login tokens, or other private site credentials.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341