rootpwn

high · CVSS v3 8.1 · EPSS 0.00136

CVE-2026-86814

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before u

Overview

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account. This flaw enables attackers to impersonate any account if they control the email via a provider account. It is a high severity vulnerability.

Description

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

Impact

Confidentiality, Integrity, and Availability are compromised as attackers can gain unauthorized access to any user account, including administrators, potentially altering site content and settings. Defenders are impacted by the risk of data breach, loss of control, and possible downtime if the site is compromised.

Remediation

Update UsersWP to version 1.5.10 or later. If an update is not immediately possible, disable social login functionality or enforce manual email verification for all social login attempts. Monitor login logs for suspicious activity and apply any vendor patches as soon as they are released.

Risk context

The vulnerability has a high CVSS v3 score of 8.1, indicating significant impact, but the EPSS of 0.00136 suggests a low probability of exploitation. Defenders should prioritize patching promptly to mitigate potential damage.

Affected products

  • UsersWP WordPress plugin

Scores

Severity
high
CVSS v2
7.6
CVSS v3
8.1
CVSS v4
EPSS
0.00136

wordpress plugin social-login authentication high-severity email-verification unauthenticated

← All CVEs