The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-02 06:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-16261
Mitre link : CVE-2026-16261
CVE.ORG link : CVE-2026-16261
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
