Authentication Bypass Vulnerability in SignUp & SignIn Plugin for WordPress
⚠️ CVE-Referenzen:
CVE-2026-12417
WordPress - Signup & Signin - CRITICAL - CVE-2026-12417.
The SignUp & SignIn plugin for WordPress is vulnerable to an authentication bypass that allows unauthenticated attackers to change user passwords, leading to potential account takeovers. The vulnerability arises from the `pravel_change_password()` AJAX handler, which lacks nonce verification and capability checks, enabling attackers to manipulate user passwords without authorization. By sending a specifically crafted POST request, an attacker can reset any user's password, including administrators, and gain full control over their accounts. This loophole poses a significant risk to the security of WordPress websites utilizing the affected plugin, making prompt action essential to secure the site.
Quelle: securityvulnerability.io