A critical security flaw, tracked as CVE-2026-15341, affects the User Session Synchronizer plugin for WordPress. This vulnerability allows unauthenticated attackers (people with no existing access to your site) to take over any user account on your site, including full administrator accounts, without needing to know any of your site's passwords or private security details.
All versions of the User Session Synchronizer plugin up to and including version 1.4.0 are impacted by this issue. If exploited, an attacker could gain complete control of your WordPress site, make unauthorized changes, access sensitive user or business data, or lock you out of your own account with no warning.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341