OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-19125

HIGH · CVSS 8.1 EPSS 0.64%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The EthPress – Web3 Login plugin for WordPress is vulnerable to an authentication bypass due to a flaw in the verify_login() function, which allows attackers to log in as any user, including administrators, by exploiting a signature verification failure. This vulnerability poses a significant risk of full site takeover, making it critical for all WordPress sites using this plugin, especially those with administrative users, to prioritize immediate patching or removal of the affected version. Users and administrators of WordPress sites leveraging this plugin should take urgent action to mitigate the risk of unauthorized access.

CVE
CVE-2026-19125
Severity
HIGH
CVSS
8.1
EPSS
0.64%
WordPress

Original NVD Description

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executing, causing unconditional fall-through to the login block where Address::log_in() calls wp_set_auth_cookie() regardless of whether the submitted signature is valid. This makes it possible for unauthenticated attackers to log in as any WordPress user who has a linked wallet address — including administrators — by submitting that user's public wallet address alongside an arbitrary well-formed signature, enabling full site takeover.