Identity Validation Flaw in Login-Social WordPress Plugin by WordPress
CVE-2026-16261
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 2 August 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-16261?
The Login-Social plugin for WordPress versions up to 1.0.4 has a critical flaw that allows attackers to bypass authentication mechanisms. It fails to verify password-reset requests against a secure reset key or the identity of the requester, leading to grave security risks. Unauthenticated attackers can exploit this vulnerability to reset any user's password or gain admin access by logging in as any existing account. This not only compromises user accounts but also jeopardizes the entire site’s integrity.
Affected Version(s)
login-social 0 <= 1.0.4
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.