๐Ÿ” CVE Alert

CVE-2026-18468

UNKNOWN 0.0

Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.

Vendor unknown
Product login & register forms
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for unknown login & register forms

Be the first to know when new unknown vulnerabilities affecting unknown login & register forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Login & Register Forms
3.2.5 < 4.0.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0b567954-4bcc-4e2a-a2b5-024175012a19/

Credits

Artus KG WPScan