CVE-2026-16261 PUBLISHED

Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover

Assigner: WPScan
Reserved: 20.07.2026 Published: 02.08.2026 Updated: 02.08.2026

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.

Product Status

Vendor Unknown
Product login-social
Versions Default: unknown
  • affected from 0 to 1.0.4 (incl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE