CVE-2026-16259
Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.
| Vendor | unknown |
| Product | uix usercenter |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown uix usercenter
Be the first to know when new unknown vulnerabilities affecting unknown uix usercenter are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Uix UserCenter
0 โค 1.0.3
References
Credits
moonge WPScan