Authentication Bypass Vulnerability in EthPress Web3 Login Plugin for WordPress
CVE-2026-19125

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
23 September 2026

What is CVE-2026-19125?

The EthPress – Web3 Login plugin for WordPress presents a serious vulnerability that allows unauthenticated attackers to bypass authentication measures. This flaw originates from the verify_login() function in app/Login.php, which lacks a required return statement in the event of signature verification failure. As a result, the function may incorrectly process login attempts, permitting attackers to log in as any WordPress user, including those with admin privileges, by submitting a valid public wallet address and a crafted signature. This vulnerability poses a significant risk of unauthorized access and potential full site takeover.

Affected Version(s)

EthPress – Web3 Login 0 <= 2.3.5

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thatchapol Booranatanit (AliceZz)
.