Junglewise Threat Intelligence

CVE-2026-18468: WordPress Login & Register Forms account takeover via password reset

CVE-2026-18468 · Severity: high · CVSS 8.1 · Published 2026-08-10

Technologies: Wordpress Login & Register Forms. Vendors: Wordpress.

Executive brief

The Login & Register Forms WordPress plugin before 4.0.2 contains a critical flaw in its password reset feature that allows attackers to take over any user account, including administrator accounts, without knowing the original password. When the plugin is configured to use verification codes for password resets (a non-default mode), an unauthenticated attacker can reset another user's password by spoofing an IP address header, gaining immediate access to accounts including those with full administrative control over the website.

Technical details

The plugin fails to bind password reset verification state to the user account or the authenticating party, instead keying it solely on the client-supplied IP address from the X-Real-IP or X-Forwarded-For headers. This allows an attacker who knows a victim's IP address (or can guess it) to bypass the verification code requirement and set a new password without ever receiving the emailed verification code. The vulnerability requires the non-default "Send Verification Code" reset mode to be enabled and affects versions 3.2.5 through 4.0.1. The verification state is never consumed after a password reset, making the attack repeatable for 24 hours from a single victim verification. Fixed in version 4.0.2.

Affected products

  • WordPress Login & Register Forms 3.2.5 to 4.0.1

Timeline

  • 2026-08-10: disclosed
  • 2026-08-10: patched: Version 4.0.2 fixes the vulnerability

References

Related threats