CVE-2026-15341 (matched: wordpress)

  • Monday, 17th August, 2026
  • 04:04am

A security vulnerability tracked as CVE-2026-15341 impacts the User Session Synchronizer plugin for WordPress, with all versions up to and including 1.4.0 affected. This flaw allows unauthenticated attackers to completely bypass login requirements to take over any user account on an affected site, including administrator accounts that have full control over website content, settings, and user data.

The issue occurs because the plugin does not perform required security checks on requests to its built-in session synchronization tool, which runs automatically on every site visit. An attacker only needs to know or guess the email address of a user on the site to send a specially crafted request that tricks the plugin into logging them in as that user, with no need for passwords, access tokens, or any other private site credentials.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341

« Back