---
id: CVE-2026-92965
title: >-
  The TikTok WordPress plugin before 1.4.2 does not check that a request is
  authorised before acting on a sign-in code supplied in the URL, so any visitor
  can make the site redeem a code of their choosing against the advertising
  platform, …
summary: >-
  The TikTok WordPress plugin before 1.4.2 does not check that a request is
  authorised before acting on a sign-in code supplied in the URL, so any visitor
  can make the site redeem a code of their choosing against the advertising
  platform, …
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-862
product: TikTok
affected:
  - TikTok >= 1.2.0 < 1.4.2
published: '2026-09-20'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92965'
references:
  - url: 'https://wpscan.com/vulnerability/e74a467a-9eb1-4da3-933a-879c9c026f4f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00154
epssPercentile: 0.04902
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-20T13:52:27.528224Z'
ingestedAt: '2026-09-20T07:16:12.219Z'
---

## Overview

The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code supplied in the URL, so any visitor can make the site redeem a code of their choosing against the advertising platform, using the site's own credentials. It matches that code loosely, so URLs that merely resemble the expected one trigger it too, and the callback runs on every request to the site rather than only on the administrator's sign-in.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
