Description
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
Published: 2026-08-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Login & Register Forms WordPress plugin fails to tie the password reset verification state to the specific account or the verifier; instead it depends on an address header supplied by the client. Because this value is controllable by an unauthenticated user, anyone who can craft such a header can complete the reset verification process and effectively assume control of any user account that has recently reset its password, including administrative accounts. This gives an attacker full read, write, and administrative privileges on the compromised account, allowing complete compromise of confidentiality, integrity, and availability of that account's data and capabilities.

Affected Systems

All installations of the Login & Register Forms plugin rated prior to version 4.0.2 are affected. The plugin is distributed by an unnamed vendor within the WordPress ecosystem.

Risk and Exploitability

The vulnerability can be exploited remotely without any user interaction beyond initiating a password reset. Because the attacker only needs to supply a crafted address header, the attack vector is straightforward for a remote adversary. No additional conditions such as elevated privileges or knowledge of a specific user are stated in the advisory. The CVSS score is 8.1, the EPSS score is < 1%, and it is not listed in CISA KEV; nevertheless, the flaw presents a high potential for exploitation and a consequential impact.

Generated by OpenCVE AI on August 13, 2026 at 11:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Login & Register Forms plugin to version 4.0.2 or later to eliminate the unauthenticated reset‑verification flaw.
  • If an upgrade is not immediately possible, disable or restrict the password reset endpoint for unauthenticated users using a firewall rule or security plugin, preventing the exploit from reaching the vulnerable code.
  • Configure any server‑side or security‑plugin rules to discard user‑supplied address headers on requests to the password reset endpoint, ensuring only server‑controlled headers are used.

Generated by OpenCVE AI on August 13, 2026 at 11:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Tue, 11 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Mon, 10 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
Title Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-11T20:15:56.501Z

Reserved: 2026-07-31T09:01:52.632Z

Link: CVE-2026-18468

cve-icon Vulnrichment

Updated: 2026-08-11T20:15:53.694Z

cve-icon NVD

Status : Deferred

Published: 2026-08-10T07:16:50.047

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-18468

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:45:03Z

Weaknesses