The UsersWP WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.
CVE-2026-86814
NONE
EPSS 0.14%
Updated Sep 19, 2026
Unknown
unknown:userswp
CVE Details
CVE ID
CVE-2026-86814
Published Date
Sep 19, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.4th percentile (higher than 3.4% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory