CVE-2026-18468
Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
| Vendor | unknown |
| Product | login & register forms |
| Published | Aug 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown login & register forms
Be the first to know when new unknown vulnerabilities affecting unknown login & register forms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Login & Register Forms
3.2.5 < 4.0.2
References
Credits
Artus KG WPScan