CVE-2026-18052

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-22 06:16

Updated : 2026-08-26 16:30


NVD link : CVE-2026-18052

Mitre link : CVE-2026-18052

CVE.ORG link : CVE-2026-18052


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication