Identity Validation Flaw in Login-Social WordPress Plugin by WordPress
CVE-2026-16261

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
2 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-16261?

The Login-Social plugin for WordPress versions up to 1.0.4 has a critical flaw that allows attackers to bypass authentication mechanisms. It fails to verify password-reset requests against a secure reset key or the identity of the requester, leading to grave security risks. Unauthenticated attackers can exploit this vulnerability to reset any user's password or gain admin access by logging in as any existing account. This not only compromises user accounts but also jeopardizes the entire site’s integrity.

Affected Version(s)

login-social 0 <= 1.0.4

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Khaled Alenazi (Nxploited)
WPScan
.