CVE-2026-18468
Last modified
CVE-2026-18468 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Login & Register Forms | >= 3.2.5, < 4.0.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-18468?
How severe is CVE-2026-18468?
How do I fix CVE-2026-18468?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-18461Use of Externally-Controlled Format String vulnerability in …9.2
- CVE-2026-18462Integer Overflow or Wraparound, Improper Access Control vuln…7.3
- CVE-2026-18464The WP MAPS PRO WordPress plugin before 6.1.3 does not perfo…7.5
- CVE-2026-18465The WP MAPS PRO WordPress plugin before 6.1.3 does not perfo…6.5
- CVE-2026-18466The WP Maps WordPress plugin before 4.9.8 does not perform …5.4
- CVE-2026-18467The Paytium: Mollie payment forms & donations plugin for Wor…9.8
- CVE-2026-18469The Login & Register Forms WordPress plugin before 4.0.2 do…8.1
- CVE-2026-1847Inserting certain large documents into a replica set could l…7.5
- CVE-2026-18470The Login & Register Forms WordPress plugin before 4.0.2 do…7.5
- CVE-2026-18473The WP Directory Kit WordPress plugin before 1.5.5 does not …9.1
- CVE-2026-18474The WP Directory Kit WordPress plugin before 1.5.6 does not …8.6
- CVE-2026-18477A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU ta…4.4
Are you affected by CVE-2026-18468?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
