CVE-2026-15341: User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters

Published Aug 15, 2026
·
Updated

The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The synchronizesession() function, hooked on init and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied ussync-key, ussync-token, and ussync-ref parameters; when ussync-key references an unregistered slot, getoption() returns false for both the secret key and the domain list, causing the AES-256-CBC encryption key to degrade to the fully predictable md5('') and the referer allowlist to collapse to an empty-string match, while the AES IV is unconditionally hard-coded as md5('another-secret'). This makes it possible for unauthenticated attackers to supply a crafted request encrypting any known or guessable user email address in the ussync-ref parameter, causing the handler to call wpsetauthcookie() for the matched user and granting full authentication as that user — including administrators — with no prior knowledge of site secrets.

Affected Software

1 affected component
WordPress User Session Synchronizer plugin<=1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade User Session Synchronizer (WordPress plugin) to a version that resolves this vulnerability.

    Fixed in 1.4.0
  2. Configuration

    Update/adjust the plugin so authenticate/session synchronization requests require nonce, capability, and shared-secret validation, rather than accepting attacker-supplied ussync-key, ussync-token, and ussync-ref parameters.

    User Session Synchronizer (WordPress plugin) ussync-key / ussync-token / ussync-ref request validation = require nonce, capability, and shared-secret validation

Event History

Aug 15, 2026
CVE Published
via MITRE·02:26 AM
Data Sourced
via MITRE·02:26 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-15341?

The severity of CVE-2026-15341 is rated as critical, with a score of 9.8.

2

How do I fix CVE-2026-15341?

To fix CVE-2026-15341, update the User Session Synchronizer plugin to a version later than 1.4.0.

3

What kind of vulnerability is CVE-2026-15341?

CVE-2026-15341 is an unauthenticated authentication bypass vulnerability that can lead to account takeover.

4

Which software is affected by CVE-2026-15341?

CVE-2026-15341 affects the User Session Synchronizer plugin for WordPress, specifically versions up to and including 1.4.0.

5

What are the potential impacts of CVE-2026-15341?

Exploitation of CVE-2026-15341 can result in unauthorized access to user accounts, leading to account takeover.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203