CVE-2026-86709: The Pressengine <= 1.0 - Unauthenticated Authentication Bypass
Published Sep 17, 2026
·Updated
The Pressengine WordPress plugin through 1.0 does not stop its login handler from issuing a session when authentication fails, allowing unauthenticated attackers to log in as any user, including administrators.
Affected Software
1 affected component
Pressengine WordPress plugin<=1.0
Event History
Sep 17, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote attacker can exploit the affected login handler. The issue can allow login as any user account, including administrator accounts.
2
Are administrator accounts at risk?
Yes. The affected behavior can allow an attacker to obtain a session as any user, including an administrator, if the site uses the vulnerable Pressengine WordPress plugin through version 1.0.