What is CVE-2026-18468?
CVE-2026-18468 affects the 'Login & Register Forms' WordPress plugin before version 4.0.2, where password reset verification is not properly bound to the target account. This flaw allows unauthenticated attackers to hijack arbitrary user accounts by manipulating the client-controlled verification value. Users should immediately update the plugin to version 4.0.2 or later.
Azərbaycanca: CVE-2026-18468, 'Login & Register Forms' WordPress plaginində parol sıfırlama prosesinin zəif bağlanması ilə bağlıdır. Plagin 4.0.2 versiyasından əvvəlki versiyalarda parol sıfırlama təsdiqini hədəf hesaba düzgün bağlamadığı üçün, autentifikasiya olunmamış hücumçulara istənilən hesabı ələ keçirməyə imkan verir. Plagin dərhal 4.0.2 və ya daha yuxarı versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which WordPress plugin is affected by CVE-2026-18468?
CVE-2026-18468 affects the 'Login & Register Forms' plugin.
To which version should the plugin be updated to protect against this vulnerability?
The plugin should be updated to version 4.0.2 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.