CVE & Vulnerabilities · August 31, 2026
A flaw in the Uix UserCenter WordPress plugin (through version 1.0.3) lets anyone forge the authentication token used by its unauthenticated profile-update feature, because that token is signed with a hardcoded key shared by every installation of the plugin. Attackers can use a forged token to change any user's email and password, including an administrator's, resulting in a complete account takeover with no login required.
// source: nvd.nist.gov ↗