What is CVE-2026-18469?
CVE-2026-18469 is a critical vulnerability in the "Login & Register Forms" WordPress plugin before version 4.0.2, where the password reset attempt limit relies on client-controlled data instead of a server-derived value. This allows unauthenticated attackers to bypass the limit and perform brute-force attacks to compromise accounts. Immediate update to the latest plugin version is strongly recommended.
Azərbaycanca: CVE-2026-18469, "Login & Register Forms" WordPress plaginin 4.0.2-dən əvvəlki versiyalarında aşkar edilmiş kritik boşluqdur. Zəiflik parol sıfırlama limitinin müştəri tərəfindən idarə olunan məlumatlarla yoxlanılması səbəbindən autentifikasiyasız hücumçulara limiti sıfırlamağa imkan verir ki, bu da brute-force hücumları ilə hesabın ələ keçirilməsinə səbəb ola bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which WordPress plugin is affected by CVE-2026-18469?
The "Login & Register Forms" plugin.
What can an attacker achieve by exploiting this vulnerability?
Unauthenticated attackers can bypass the password reset limit and perform brute-force attacks to compromise accounts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.