PT-2026-83394 · WordPress · Uix Usercenter
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Uix UserCenter versions prior to 1.0.4
Description
The Uix UserCenter WordPress plugin fails to verify if the account being modified during an unauthenticated profile-update action belongs to the requester. The process uses a token for authentication that relies on a hardcoded signing key identical across all installations. This allows unauthenticated attackers to forge tokens for any user, overwrite the email and password of an administrator, and gain full control of the account.
Recommendations
Update Uix UserCenter to version 1.0.4 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uix Usercenter