CyberRota Analysis
AI-GeneratedThe Pressengine WordPress plugin versions up to 1.0 are vulnerable as they improperly handle session creation during failed authentication attempts, enabling unauthenticated attackers to gain access as any user, including those with administrative privileges. This poses a significant security risk, particularly for websites that rely on this plugin for user management. WordPress site administrators using the Pressengine plugin should prioritize immediate updates or mitigations to protect against potential unauthorized access.
Original NVD Description
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.