---
id: CVE-2026-86814
title: >-
  The UsersWP  WordPress plugin before 1.5.10 does not verify that a social
  login provider has confirmed ownership of an email address before using it to
  resolve an existing account, allowing unauthenticated attackers to log in as
  any user…
summary: >-
  The UsersWP  WordPress plugin before 1.5.10 does not verify that a social
  login provider has confirmed ownership of an email address before using it to
  resolve an existing account, allowing unauthenticated attackers to log in as
  any user…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: UsersWP
affected:
  - UsersWP < 1.5.10
published: '2026-09-19'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T13:34:57.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86814'
references:
  - url: 'https://wpscan.com/vulnerability/f606cf7b-cef8-4b2c-819a-6d3e6adeacee/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00383
epssPercentile: 0.29665
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-19T13:12:19.268966Z'
ingestedAt: '2026-09-19T06:59:13.114Z'
---

## Overview

The UsersWP  WordPress plugin before 1.5.10 does not verify that a social login provider has confirmed ownership of an email address before using it to resolve an existing account, allowing unauthenticated attackers to log in as any user, including administrators, whose email address they can assert through a provider account of their own.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
