Executive brief
The Branda plugin for WordPress, used for white-labeling and customizing login screens, contains a critical security flaw that allows unauthorized individuals to take over user accounts. By exploiting a weakness in how the plugin handles password updates, an attacker can change the password of any user, including site administrators. This could lead to a total loss of control over the website, data theft, or the installation of malicious software.
Technical details
The Branda plugin for WordPress (versions up to 3.4.29) is vulnerable to an unauthenticated account takeover due to a weak password recovery mechanism (CWE-640). The root cause is located in the signup-password.php component, where the plugin fails to properly validate a user's identity or verify a secure token before allowing a password update. An unauthenticated remote attacker can exploit this by sending a crafted request to change the password of any arbitrary user, including those with administrative privileges. This leads to full site compromise. A patch has been released in the plugin's trunk (changeset 3568291).
Affected products
- WPMU DEV Branda – White Label & Branding, Free Login Page Customizer up to and including 3.4.29
Timeline
- 2026-06-19: disclosed: Vulnerability reported by Wordfence
- 2026-06-20: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/branda-white-labeling/tags/3.4.29/inc/modules/login-screen/signup-password.php
- https://plugins.trac.wordpress.org/changeset/3568291/branda-white-labeling/trunk/inc/modules/login-screen/signup-password.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/56f13af3-71b6-42d4-9fda-a75778f32091?source=cve