---
id: CVE-2026-18052
title: >-
  The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account
  being logged in to the signature which authorises the login, nor prevent an
  already used login link from being replayed, allowing attackers who obtain
  such a li…
summary: >-
  The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account
  being logged in to the signature which authorises the login, nor prevent an
  already used login link from being replayed, allowing attackers who obtain
  such a li…
severity: none
published: '2026-08-22'
updated: '2026-08-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18052'
references:
  - url: 'https://wpscan.com/vulnerability/e1e8c313-f7ea-4f3a-85c0-4f33dfe0710d/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00271
epssPercentile: 0.19766
ingestedAt: '2026-08-23T04:42:12.988Z'
---

## Overview

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
