CVE-2026-16259 PUBLISHED

Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation

Assigner: WPScan
Reserved: 20.07.2026 Published: 29.08.2026 Updated: 29.08.2026

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.

Product Status

Vendor Unknown
Product Uix UserCenter
Versions Default: unknown
  • affected from 0 to 1.0.3 (incl.)

Credits

  • moonge finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE