Impact
The ManageWP Worker WordPress plugin fails to bind the account to the signature used for auto‑login and does not prevent a login link from being replayed, resulting in a CWE‑287 Authentication Bypass. This oversight allows an attacker who obtains such a link to hijack a session and gain the privileges of any user on the site, including administrative control.
Affected Systems
All installations of the ManageWP Worker plugin running versions earlier than 4.9.37 are affected. The vulnerability impacts any WordPress site that has been compromised by a login link or whose link is exposed to an attacker.
Risk and Exploitability
The vulnerability constitutes a high‑risk authentication bypass with a CVSS score of 8.1, indicating substantial impact. The EPSS score is less than 1%, suggesting a low probability of exploitation yet still notable. It is not listed in the CISA KEV catalog. The attack vector is almost certainly remote, requiring only that an attacker obtain or guess a valid auto‑login link; because the plugin does not bind the session to the user account, replaying the link provides immediate and complete access to the target site.
OpenCVE Enrichment