{"id":"CVE-2026-16261","title":"The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthent…","summary":"The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthent…","severity":"none","published":"2026-08-02","updated":"2026-08-02","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-16261","references":[{"url":"https://wpscan.com/vulnerability/533f9347-e7cd-4a86-8cb5-f6d4aaaf4dd1/","label":"contact@wpscan.com"}],"tags":["nvd"],"ingestedAt":"2026-08-02T13:18:29.348Z","epss":0.00333,"epssPercentile":0.26761,"slug":"CVE-2026-16261","body":"## Overview\n\nThe login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}