cvefeed.io
Critical Authentication Bypass Vulnerability in WordPress Plugin CVE-2026-15341
Article Content
The User Session Synchronizer plugin for WordPress is critically vulnerable to an authentication bypass, allowing unauthenticated attackers to take over user accounts, including administrators. The vulnerability, identified as CVE-2026-15341, affects all versions up to and including 1.4.0. It arises from the `synchronize_session()` function, which fails to validate attacker-supplied parameters, leading to predictable encryption keys. Attackers can exploit this flaw by sending crafted requests with known user email addresses, thereby gaining full authentication without prior knowledge of site secrets. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Currently, there is no public proof-of-concept or evidence of active exploitation. Users are advised to update the plugin or disable it if not in use, and restrict access to WordPress admin areas while patches are being deployed.
Key Points: • CVE-2026-15341 allows unauthenticated attackers to bypass authentication in WordPress. • The vulnerability affects all versions of the User Session Synchronizer plugin up to 1.4.0. • No evidence of active exploitation has been reported, but the CVSS score is critically high at 9.8.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.