CVE-2026-15341 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 22:04pm

A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, impacting all versions of the plugin up to and including 1.4.0. The flaw allows unauthenticated attackers (users who do not have valid login credentials for your site) to bypass all login checks and take full control of any account on your WordPress site, including administrator accounts. Attackers do not need to know any of your site's private passwords or security secrets to exploit this issue.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341

« Back