CRITICAL
Pressengine
CVE published 2026-09-17
CVE-2026-86709
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators. This vulnerability allows for unauthorized access and control, potentially leading to lateral movement and exploitation of additional vulnerabilities. Defenders responsible for WordPress installati [truncated]