Impact
The Pressengine WordPress plugin through version 1.0 fails to terminate a session when authentication fails, allowing attackers to obtain a valid session as any user, including administrators. This blind authentication bypass grants full control over the WordPress installation and enables complete compromise of site data and configuration. The weakness aligns with CWE-287.
Affected Systems
WordPress sites installing the Pressengine plugin up to and including version 1.0 are affected. The vendor is listed as Unknown: The Pressengine, and any deployment of this plugin on a server running WordPress is vulnerable.
Risk and Exploitability
The CVSS score of 9.8 classifies this as critical, indicating a high likelihood of severe impact if exploited. EPSS is under 1 %, suggesting a low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would most likely exploit this via the plugin’s authentication endpoint over the web, submitting crafted credentials to trigger the session creation even on login failure. No additional prerequisites are noted beyond web access to the affected site.
OpenCVE Enrichment