What is CVE-2026-15341?
The User Session Synchronizer plugin for WordPress (versions up to 1.4.0) contains an authentication bypass vulnerability via the `synchronize_session()` function, which lacks nonce and capability checks. This flaw can lead to remote account takeover; users should immediately update or deactivate the plugin.
Azərbaycanca: User Session Synchronizer WordPress plaginində (1.4.0 və əvvəlki versiyalar) aşkarlanan bu boşluq `synchronize_session()` funksiyası vasitəsilə autentifikasiyadan yan keçməyə imkan verir. Zəiflik uzaqdan hesab ələ keçirməyə (Account Takeover) səbəb ola bilər; istifadəçilər ən qısa zamanda plaqini yeniləməli və ya deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
Which function in the User Session Synchronizer plugin allows the authentication bypass in CVE-2026-15341?
The vulnerability is exploited via the `synchronize_session()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.