CVE-2026-18468: Login & Register Forms < 4.0.2 - Unauthenticated Account Takeover via Password Reset Verification State Keyed on a Client-Supplied Address Header
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18468?
The severity of CVE-2026-18468 is rated at 83, indicating a high risk of impact.
How do I fix CVE-2026-18468?
To fix CVE-2026-18468, upgrade the Login & Register Forms WordPress plugin to version 4.0.2 or later.
What exploit is associated with CVE-2026-18468?
CVE-2026-18468 allows unauthenticated attackers to take over accounts via a vulnerability in the password reset mechanism.
Which software is impacted by CVE-2026-18468?
CVE-2026-18468 impacts the Login & Register Forms WordPress plugin versions earlier than 4.0.2.
What are the consequences of CVE-2026-18468?
The consequences of CVE-2026-18468 include unauthorized account takeover, potentially leading to data breaches or further exploits.