Critical Authentication Bypass Vulnerability in WordPress Plugin CVE-2026-15341

Critical Authentication Bypass Vulnerability in WordPress Plugin CVE-2026-15341

First seen 16 Aug 2026, 09:17 UTC Feedlycvefeed.iocve.threatint.comwww.incibe.esvulners.com 83% similarity 78.0

Article Content

Browse articles
ThreatCluster

The User Session Synchronizer plugin for WordPress is critically vulnerable to an authentication bypass, allowing unauthenticated attackers to take over user accounts, including administrators. The vulnerability, identified as CVE-2026-15341, affects all versions up to and including 1.4.0. It arises from the `synchronize_session()` function, which fails to validate attacker-supplied parameters, leading to predictable encryption keys. Attackers can exploit this flaw by sending crafted requests with known user email addresses, thereby gaining full authentication without prior knowledge of site secrets. The CVSS score for this vulnerability is 9.8, indicating a critical severity level. Currently, there is no public proof-of-concept or evidence of active exploitation. Users are advised to update the plugin or disable it if not in use, and restrict access to WordPress admin areas while patches are being deployed.

Key Points: • CVE-2026-15341 allows unauthenticated attackers to bypass authentication in WordPress. • The vulnerability affects all versions of the User Session Synchronizer plugin up to 1.4.0. • No evidence of active exploitation has been reported, but the CVSS score is critically high at 9.8.

ThreatCluster AI How this analysis works

Timeline

2026-08-15
CVE-2026-15341 published
The vulnerability was disclosed, affecting the User Session Synchronizer plugin for WordPress.
Feedly
2026-08-16
Security advisories released
Multiple sources published advisories about the critical authentication bypass vulnerability.
cvefeed.io
2026-08-16
Recommendations issued for users
Users are advised to update or disable the vulnerable plugin and restrict admin access while patches are deployed.
cve.threatint.com

Community

Browse all →

Tracked Entities in This Story