CVE-2026-16261: Unknown Login-Social
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.
Affected products
- Unknown Login-Social: up to and including 1.0.4
Published 2026-08-02. Last modified 2026-08-26.