SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-18052

HIGH · CVSS 8.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The ManageWP Worker plugin for WordPress prior to version 4.9.37 is vulnerable due to its failure to bind login sessions to unique signatures, allowing attackers to exploit reused login links. This could enable unauthorized access to user accounts, including those with administrative privileges, posing a significant security risk. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential account compromise.

CVE
CVE-2026-18052
Severity
HIGH
CVSS
8.1
EPSS
0.27%
WordPress

Original NVD Description

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.