CVE-2026-16261: Unknown Login-Social

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.

Affected products

  • Unknown Login-Social: up to and including 1.0.4

Published 2026-08-02. Last modified 2026-08-26.