CVE-2026-16259 — Uix UserCenter Hardcoded Token Key Enables Admin Takeover

CVE & Vulnerabilities · August 31, 2026

CVE & Vulnerabilities·nvd.nist.gov

A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its unauthenticated profile-update feature, because that token is signed with a hardcoded key shared by every installation of the plugin. Attackers can use a forged token to change any user's email and password, including an administrator's, resulting in a complete account takeover with no login required.

// source: nvd.nist.gov ↗

Back to Blog