A security vulnerability has been identified in the User Session Synchronizer plugin for WordPress, affecting all versions up to and including 1.4.0. This flaw allows unauthenticated attackers (people without existing login access to your site) to take over any user account on your WordPress site, including administrator accounts, with no need for your site's private credentials or secrets.
If an attacker gains control of an administrator account, they can alter your site's content, access private data, install malicious software, or take your site offline entirely, which can disrupt your business operations and damage visitor trust in your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15341