CVE-2026-18468
Received Received - Intake

Unauthenticated Account Takeover via Password Reset in Login & Register Forms WordPress Plugin

Vulnerability report for CVE-2026-18468, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: WPScan

Description

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpforms login_and_register_forms to 4.0.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Login & Register Forms WordPress plugin before version 4.0.2. It allows unauthenticated attackers to take over any user account, including administrators, by exploiting a flaw in the password reset verification process. The plugin does not properly bind the reset verification state to the specific account or user, relying instead on a client-controlled address header. Attackers can manipulate this state to hijack accounts.

Detection Guidance

Check the installed version of the Login & Register Forms WordPress plugin. If it is below 4.0.2, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

If you use the vulnerable plugin, attackers could gain full control over any user account, including admin accounts. This could lead to unauthorized access to sensitive data, website defacement, or further compromise of your WordPress site. The impact is severe as it allows persistent account takeover for up to a day after a single victim initiates a password reset.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations using the vulnerable plugin may face compliance breaches, legal penalties, and reputational damage due to potential data exposure or loss of data integrity.

Mitigation Strategies

Update the Login & Register Forms plugin to version 4.0.2 or later immediately. Disable the non-default verification-code reset mode if enabled. Monitor for suspicious account activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18468. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart