PT-2026-95759 · WordPress · Userswp
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UsersWP versions prior to 1.5.10
Description
An issue exists where the plugin fails to verify if a social login provider has confirmed ownership of an email address before using it to resolve an existing account. This allows unauthenticated attackers to perform an account takeover and log in as any user, including administrators, by asserting the target email address through a social provider account they control.
Recommendations
Update to version 1.5.10 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Userswp