SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-16259

CRITICAL · CVSS 9.8 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Uix UserCenter WordPress plugin versions up to 1.0.3 is vulnerable due to improper verification of account modifications during unauthenticated profile-update actions, allowing attackers to forge tokens and gain unauthorized access. This vulnerability can lead to account takeover, enabling attackers to overwrite an administrator's email and password. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-16259
Severity
CRITICAL
CVSS
9.8
EPSS
0.28%
WordPress

Original NVD Description

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.