CVE-2026-86814 PUBLISHED

UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email

Assigner: WPScan
Reserved: 08.09.2026 Published: 19.09.2026 Updated: 19.09.2026

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

Product Status

Vendor Unknown
Product UsersWP
Versions Default: unaffected
  • affected from 0 to 1.5.10 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE