Junglewise Threat Intelligence

CVE-2026-16259: Uix UserCenter privilege escalation via unauthenticated profile update

CVE-2026-16259 · Severity: critical · CVSS 9.8 · Published 2026-08-29

Executive brief

The Uix UserCenter WordPress plugin contains a critical authentication bypass that allows attackers to modify any user account without logging in. By exploiting a hardcoded, globally-identical signing key, attackers can impersonate any user—including administrators—change their email and password, and gain full control of the WordPress site, leading to complete compromise of the business's online presence and customer data.

Technical details

The vulnerability stems from two authentication flaws in the unauthenticated profile-update action: (1) the plugin fails to verify that the target account belongs to the requester, and (2) it uses a hardcoded, globally-identical token signing key across all installations. An unauthenticated attacker can forge a valid authentication token for any user by reusing the hardcoded key, then use that token to invoke the profile-update action and modify any account's email and password. No authentication or user interaction is required. The plugin versions through 1.0.3 are affected; no public patch status is currently known.

Affected products

  • Uix UserCenter through 1.0.3

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: advisory: CVE-2026-16259 published

References