OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-86814

HIGH · CVSS 8.1 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-19 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The UsersWP plugin for WordPress prior to version 1.5.10 is vulnerable due to inadequate verification of email ownership from social login providers, enabling unauthenticated attackers to gain access to user accounts, including those of administrators, by asserting control over an email address. This flaw poses a significant security risk for WordPress sites utilizing the plugin, particularly those with sensitive user data or administrative functions. Website administrators using the affected plugin should prioritize immediate updates to mitigate potential unauthorized access.

CVE
CVE-2026-86814
Severity
HIGH
CVSS
8.1
EPSS
0.38%
WordPress

Original NVD Description

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.