CVE-2026-16259
Received Received - Intake

Unauthenticated Account Takeover in Uix UserCenter WordPress Plugin

Vulnerability report for CVE-2026-16259, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
uix_usercenter wordpress_plugin to 1.0.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Uix UserCenter WordPress plugin version 1.0.3 or earlier. It allows unauthenticated attackers to forge tokens for any user due to a hardcoded signing key used for authentication. Attackers can then modify an administrator's email and password, gaining full control of the account.

Detection Guidance

Check if the Uix UserCenter WordPress plugin version 1.0.3 or earlier is installed. Look for unauthorized profile update actions or suspicious token generation attempts in server logs. No specific commands are provided in the context.

Impact Analysis

If you use the Uix UserCenter WordPress plugin version 1.0.3 or earlier, an attacker could take over your WordPress administrator account. This could lead to complete control over your website, including data theft, defacement, or spreading malware to visitors.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face fines or legal consequences if user data is compromised due to this flaw.

Mitigation Strategies

Immediately uninstall or disable the Uix UserCenter WordPress plugin if installed. Restrict access to WordPress admin panels and monitor for unauthorized account changes. Apply any available patches once released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16259. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart