AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18468

HIGH · CVSS 8.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Login & Register Forms plugin for WordPress versions prior to 4.0.2 is vulnerable due to improper binding of the password reset verification state, allowing unauthenticated attackers to exploit this weakness and take over accounts of users, including administrators, who have recently completed a password reset. This vulnerability poses a significant risk to any WordPress site utilizing this plugin, particularly those with user accounts that may be targeted. WordPress site administrators should prioritize updating to the latest version of the plugin to mitigate this risk.

CVE
CVE-2026-18468
Severity
HIGH
CVSS
8.1
EPSS
0.28%
WordPress

Original NVD Description

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.