PT-2026-83394 · WordPress · Uix Usercenter

·

CVE-2026-16259

·

Published

2026-08-29

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Uix UserCenter versions prior to 1.0.4
Description The Uix UserCenter WordPress plugin fails to verify if the account being modified during an unauthenticated profile-update action belongs to the requester. The process uses a token for authentication that relies on a hardcoded signing key identical across all installations. This allows unauthenticated attackers to forge tokens for any user, overwrite the email and password of an administrator, and gain full control of the account.
Recommendations Update Uix UserCenter to version 1.0.4 or later.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16259

Affected Products

Uix Usercenter