CRITICAL
rafasashi
CVE published 2026-08-15
CVE-2026-15341
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. This vulnerability allows unauthenticated attackers to supply crafted requests that can encrypt any known or guessable user email address, leading to account takeovers. The plugin's `synchronize_session()` function, hooked on `init` and executed [truncated]