Authentication Bypass in Pressengine WordPress Plugin
CVE-2026-86709

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-86709?

The Pressengine WordPress plugin, prior to version 1.0, contains a significant flaw in its login handler that fails to properly prevent session issuance upon failed authentication attempts. This vulnerability exposes the system to unauthenticated attackers who could potentially exploit this weakness to gain unauthorized access as any user, including administrators. Users are encouraged to update to the latest version to mitigate the risk associated with this vulnerability.

Affected Version(s)

The Pressengine 0 <= 1.0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Naoki Kawahigashi
WPScan
.