CVE-2026-86814
UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.
| Vendor | unknown |
| Product | userswp |
| Published | Sep 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown userswp
Be the first to know when new unknown vulnerabilities affecting unknown userswp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / UsersWP
0 < 1.5.10
References
Credits
Pedro Pinho WPScan