What is CVE-2026-18961?
CVE-2026-18961 is an authentication bypass vulnerability in VentraConnect's passwordless login plugin for WordPress (up to 1.4.3). An attacker can gain unauthorized access by exploiting the plugin's trust in an unverified email field returned by an OAuth provider. Update the plugin to the latest patched version immediately.
Azərbaycanca: CVE-2026-18961, VentraConnect-in WordPress üçün parolsuz giriş plaginində (1.4.3 və əvvəlki versiyalar) autentifikasiyadan yan keçmə zəifliyidir. OAuth təminatçısından qaytarılan təsdiqlənməmiş e-poçt sahəsinə etibar edildiyi üçün, hücumçu qurbanın e-poçtunu istifadə edərək səlahiyyətsiz giriş əldə edə bilər. Plaqini dərhal son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
How is the CVE-2026-18961 vulnerability exploited in the VentraConnect plugin?
In this vulnerability, an attacker can gain unauthorized access using a victim's email address by manipulating the unverified email field returned by the OAuth provider, because the plugin blindly trusts that field.
What measure should be taken to protect against CVE-2026-18961?
It is recommended to immediately update VentraConnect's passwordless login plugin to the latest patched version, as versions 1.4.3 and earlier are affected by this authentication bypass vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.