Authentication Bypass Vulnerability in SignUp & SignIn Plugin for WordPress
CVE-2026-12417
9.8CRITICAL
What is CVE-2026-12417?
The SignUp & SignIn plugin for WordPress is vulnerable to an authentication bypass that allows unauthenticated attackers to change user passwords, leading to potential account takeovers. The vulnerability arises from the pravel_change_password() AJAX handler, which lacks nonce verification and capability checks, enabling attackers to manipulate user passwords without authorization. By sending a specifically crafted POST request, an attacker can reset any user's password, including administrators, and gain full control over their accounts. This loophole poses a significant risk to the security of WordPress websites utilizing the affected plugin, making prompt action essential to secure the site.
Affected Version(s)
SignUp & SignIn 0 <= 1.0.0