๐Ÿ” CVE Alert

CVE-2026-86814

UNKNOWN 0.0

UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

Vendor unknown
Product userswp
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for unknown userswp

Be the first to know when new unknown vulnerabilities affecting unknown userswp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / UsersWP
0 < 1.5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/f606cf7b-cef8-4b2c-819a-6d3e6adeacee/

Credits

Pedro Pinho WPScan