What is CVE-2026-16261?
The "login-social" WordPress plugin through version 1.0.4 fails to validate password-reset requests and improperly issues sessions from unverified sign-in data. This allows unauthenticated attackers to reset any user's password or log in as any user. The plugin must be updated to the latest version or temporarily disabled immediately.
Azərbaycanca: WordPress üçün "login-social" pluginində (1.0.4 versiyasına qədər) autentifikasiya zəifliyi aşkar edilib. Bu boşluq autentifikasiya olunmamış hücumçuya istənilən istifadəçinin parolunu sıfırlamağa və ya onun adından sistemə daxil olmağa imkan verir. Plugin dərhal ən son versiyaya yenilənməli və ya müvəqqəti olaraq deaktiv edilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What can the CVE-2026-16261 vulnerability in the 'login-social' WordPress plugin lead to?
This vulnerability allows an unauthenticated attacker to reset any user's password or log in as any user.
What action should be taken to protect against CVE-2026-16261?
The plugin must be updated to the latest version or temporarily disabled immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.