OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86709

CRITICAL · CVSS 9.8 EPSS 0.63%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Pressengine WordPress plugin versions up to 1.0 are vulnerable as they improperly handle session creation during failed authentication attempts, enabling unauthenticated attackers to gain access as any user, including those with administrative privileges. This poses a significant security risk, particularly for websites that rely on this plugin for user management. WordPress site administrators using the Pressengine plugin should prioritize immediate updates or mitigations to protect against potential unauthorized access.

CVE
CVE-2026-86709
Severity
CRITICAL
CVSS
9.8
EPSS
0.63%
WordPress

Original NVD Description

The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.