CVE-2026-86814
Received Received - Intake

Unauthenticated Account Takeover in UsersWP WordPress Plugin

Vulnerability report for CVE-2026-86814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-19

Last updated on: 2026-09-19

Assigner: WPScan

Description

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-19
Last Modified
2026-09-19
Generated
2026-09-20
AI Q&A
2026-09-20
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
userswp userswp to 1.5.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the UsersWP WordPress plugin before version 1.5.10 allows attackers to log in as any user, including administrators, by exploiting social login providers. The plugin fails to verify if a social login provider has confirmed ownership of an email address before using it to resolve an existing account.

Impact Analysis

An attacker could gain unauthorized access to user accounts, including administrative accounts, potentially leading to data theft, unauthorized modifications, or complete site compromise. This could result in loss of sensitive information or control over the WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access to personal data, violating GDPR and HIPAA requirements for data protection and access control. Organizations may face legal penalties, reputational damage, and loss of compliance certifications.

Mitigation Strategies

Update the UsersWP WordPress plugin to version 1.5.10 or later to address the vulnerability. If immediate update is not possible, disable social login functionality as a temporary workaround.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart