Impact
The ManageWP Worker WordPress plugin fails to bind the account to the signature used for auto‑login and does not prevent a login link from being replayed. This oversight allows an attacker who obtains such a link to hijack a session and gain the privileges of any user on the site, including administrative control.
Affected Systems
All installations of the ManageWP Worker plugin running versions earlier than 4.9.37 are affected. The vulnerability impacts any WordPress site that has been compromised by a login link or whose link is exposed to an attacker.
Risk and Exploitability
The vulnerability constitutes a high‑risk authentication bypass, and although no CVSS score is listed, the potential for total loss of site control is significant. The EPSS score is not available, implying no publicly known exploitation data at present, and the vulnerability is currently not in the CISA KEV catalog. Nevertheless, the attack vector is almost certainly remote, requiring only that an attacker obtain or guess a valid auto‑login link. Because the plugin does not bind the session to the user account, replaying the link gives the attacker immediate and complete access to the target site.
OpenCVE Enrichment