Review
TikTok
CVE published 2026-09-20
CVE-2026-92965
The TikTok WordPress plugin before 1.4.2 has a vulnerability that allows any visitor to redeem a sign-in code of their choice against the advertising platform, using the site's own credentials. This is possible because the plugin does not check if a request is authorized before acting on a sign-in code supplied in the URL. The vulnerability can lead to unauthorized access to the advertising platform, pote [truncated]