high · CVSS v3 8.1 · EPSS 0.00136
CVE-2026-86814
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before u
Overview
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account. This flaw enables attackers to impersonate any account if they control the email via a provider account. It is a high severity vulnerability.
Description
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.
Impact
Confidentiality, Integrity, and Availability are compromised as attackers can gain unauthorized access to any user account, including administrators, potentially altering site content and settings. Defenders are impacted by the risk of data breach, loss of control, and possible downtime if the site is compromised.
Remediation
Update UsersWP to version 1.5.10 or later. If an update is not immediately possible, disable social login functionality or enforce manual email verification for all social login attempts. Monitor login logs for suspicious activity and apply any vendor patches as soon as they are released.
Risk context
The vulnerability has a high CVSS v3 score of 8.1, indicating significant impact, but the EPSS of 0.00136 suggests a low probability of exploitation. Defenders should prioritize patching promptly to mitigate potential damage.
Affected products
- UsersWP WordPress plugin
Scores
- Severity
- high
- CVSS v2
- 7.6
- CVSS v3
- 8.1
- CVSS v4
- —
- EPSS
- 0.00136