CVE-2026-18052
ManageWP Worker < 4.9.37 - Unauthenticated Authentication Bypass via Unsigned Auto-Login Parameters
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
| Vendor | unknown |
| Product | managewp worker |
| Published | Aug 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown managewp worker
Be the first to know when new unknown vulnerabilities affecting unknown managewp worker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / ManageWP Worker
0 < 4.9.37
References
Credits
Jakub Herman WPScan