Junglewise Threat Intelligence

CVE-2026-86814: UsersWP Social Login authentication bypass in email verification

CVE-2026-86814 · Severity: high · CVSS 8.1 · Published 2026-09-19

Executive brief

UsersWP is a WordPress plugin that allows users to log in using social media accounts. The plugin fails to verify that a social login provider has confirmed ownership of an email address before using it to match existing user accounts. An attacker can register with any email address at a social provider they control and gain access to any WordPress account associated with that email, including administrator accounts.

Technical details

The plugin does not validate that a social login provider has confirmed email ownership before resolving existing accounts by email. An unauthenticated attacker can assert any email address through a provider account they control to hijack accounts. This is a broken authentication vulnerability (CWE-269) allowing account takeover via privilege escalation. The vulnerability affects versions before 1.5.10 and has been patched.

Affected products

  • UsersWP Social Login before 1.5.10

Timeline

  • 2026-09-17: disclosed
  • 2026-09-19: patched: version 1.5.10

References