PT-2026-97598 · WordPress · Ethpress

·

CVE-2026-19125

·

Published

2026-09-23

·

Updated

2026-09-24

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EthPress – Web3 Login plugin for WordPress versions prior to 2.3.6
Description An authentication bypass exists due to a missing return statement in the verify login() function within app/Login.php. When the Signature::verify2() function detects a signature mismatch, the system assigns an error to a local variable but continues execution. This leads to an unconditional fall-through to the login block where Address::log in() invokes wp set auth cookie(), granting access regardless of signature validity. Unauthenticated attackers can log in as any user with a linked wallet address, including administrators, by providing the public wallet address and an arbitrary well-formed signature, potentially leading to full site takeover.
Recommendations Update the plugin to a version newer than 2.3.5. As a temporary mitigation, restrict access to the verify login() function or the login functionality provided by the plugin until the update is applied.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19125

Affected Products

Ethpress