UsersWP - Social Login < 1.5.10 - Unauthenticated Account Takeover via Unverified Provider Email
Summary
| CVE | CVE-2026-86814 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-19 07:16:33 UTC |
| Updated | 2026-09-19 07:16:33 UTC |
| Description | The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own. |
Risk And Classification
Problem Types: CWE-269 Improper Privilege Management
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/f606cf7b-cef8-4b2c-819a-6d3e6adeacee | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Pedro Pinho (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.