SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-16261

HIGH · CVSS 7.5 EPSS 0.33%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The login-social WordPress plugin versions up to 1.0.4 are vulnerable due to inadequate validation of password-reset requests, allowing unauthenticated attackers to reset any user's password or gain access to accounts, including those of administrators. This flaw poses a significant risk of site takeover, making it critical for WordPress site administrators and users of the affected plugin to prioritize immediate updates or mitigations. Organizations relying on this plugin should assess their exposure and implement necessary security measures to protect against potential exploitation.

CVE
CVE-2026-16261
Severity
HIGH
CVSS
7.5
EPSS
0.33%
WordPress

Original NVD Description

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.