CVE-2026-18052 PUBLISHED

ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login Parameters

Assigner: WPScan
Reserved: 28.07.2026 Published: 22.08.2026 Updated: 22.08.2026

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.

Product Status

Vendor Unknown
Product ManageWP Worker
Versions Default: unaffected
  • affected from 0 to 4.9.37 (excl.)

Credits

  • Jakub Herman finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE