CVE-2026-16261: Huge IT Login <= 1.0.4 - Unauthenticated Account Takeover
The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it issues authentication sessions from unverified third-party sign-in data, allowing unauthenticated attackers to reset any user's password or log in as any existing account, including administrators, and take over the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16261?
CVE-2026-16261 has a severity score of 95, indicating a critical risk level.
How do I fix CVE-2026-16261?
To fix CVE-2026-16261, update the login-social WordPress plugin to version 1.0.5 or later.
What does CVE-2026-16261 allow an attacker to do?
CVE-2026-16261 allows unauthenticated attackers to reset any user's password or log in as any user.
Which versions of the login-social plugin are affected by CVE-2026-16261?
CVE-2026-16261 affects the login-social WordPress plugin versions up to and including 1.0.4.
Is user data at risk due to CVE-2026-16261?
Yes, user data is at risk because the vulnerability enables unauthorized access to user accounts.