Skip to main content
Vulnerability Database/CVE-2026-86814

CVE-2026-86814: UsersWP WordPress Auth Bypass Vulnerability

CVE-2026-86814 is an authentication bypass flaw in UsersWP WordPress plugin that lets attackers log in as any user by exploiting social login providers. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-86814 Overview

CVE-2026-86814 is an authentication bypass vulnerability in the UsersWP WordPress plugin versions prior to 1.5.10. The plugin fails to verify that a social login provider has confirmed ownership of an email address before matching it to an existing WordPress account. Unauthenticated attackers can log in as any user, including administrators, by asserting a target's email address through an attacker-controlled provider account. The flaw is categorized under [CWE-269] Improper Privilege Management.

Critical Impact

Unauthenticated attackers can gain administrator access to affected WordPress sites by leveraging unverified email assertions from social login providers, leading to full site compromise.

Affected Products

  • UsersWP WordPress plugin versions before 1.5.10
  • WordPress sites with UsersWP social login functionality enabled
  • Any UsersWP deployment relying on third-party OAuth or social identity providers for authentication

Discovery Timeline

  • 2026-09-19 - CVE-2026-86814 published to NVD
  • 2026-09-21 - Last updated in NVD database

Technical Details for CVE-2026-86814

Vulnerability Analysis

The UsersWP plugin implements social login functionality that resolves external identities to existing WordPress accounts using the email address returned by the identity provider. The plugin trusts the returned email address without checking whether the provider marked the email as verified.

An attacker registers an account at a supported social provider using the email address of a target WordPress user. When the attacker initiates social login against the WordPress site, UsersWP matches the asserted email to the existing local account and issues an authenticated session for that user. No password, multi-factor challenge, or ownership proof is required.

The impact scales with the privilege of the targeted account. Compromise of an administrator email address grants full site control, including plugin installation, content modification, and pivot opportunities to underlying infrastructure.

Root Cause

The root cause is missing validation of the email_verified claim (or equivalent) returned by social login providers. Providers such as Google, Facebook, and others expose signals indicating whether an email has been verified by the user. UsersWP treats the asserted email as authoritative and uses it as the sole account lookup key during login resolution.

Attack Vector

Exploitation requires network access to the WordPress login flow and the ability to create an account at any social provider integrated with UsersWP. The attacker sets the provider account's email address to that of a target WordPress user, then completes the social login flow against the vulnerable site. UsersWP resolves the login to the target's local account and authenticates the attacker.

No authentication is required prior to exploitation. User interaction is limited to the attacker completing the OAuth flow. See the WPScan Vulnerability Report for additional technical detail.

Detection Methods for CVE-2026-86814

Indicators of Compromise

  • Successful WordPress login events for administrator accounts originating from social login endpoints without prior provider linkage
  • New or unexpected sessions for privileged users where the authentication method is a social provider
  • Creation of new administrator users, plugin installations, or theme edits shortly after a social login event
  • WordPress wp_users or usermeta changes to email or role fields following unattended social login flows

Detection Strategies

  • Audit WordPress authentication logs for social login events targeting administrator or editor accounts
  • Compare the provider account subject identifier (sub claim) against historical values for each user; investigate mismatches
  • Alert on WordPress role escalations, plugin installations, or wp-config.php modifications immediately following a social login
  • Review the UsersWP plugin version across managed WordPress instances and flag any running versions below 1.5.10

Monitoring Recommendations

  • Ingest WordPress and web server access logs into a centralized log platform for correlation of social login flows and privileged actions
  • Monitor outbound OAuth callback traffic to identify unusual provider callbacks preceding administrative activity
  • Track file integrity for the WordPress wp-content/plugins and wp-content/themes directories to detect post-exploitation changes

How to Mitigate CVE-2026-86814

Immediate Actions Required

  • Upgrade the UsersWP plugin to version 1.5.10 or later on all WordPress installations
  • Rotate passwords and revoke active sessions for administrator and privileged user accounts
  • Review the WordPress user list for unauthorized accounts, role changes, or modified email addresses
  • Audit installed plugins, themes, and scheduled tasks (wp-cron) for unauthorized additions

Patch Information

The vendor has addressed the vulnerability in UsersWP 1.5.10. The fix enforces verification of the email ownership claim returned by social login providers before resolving to an existing account. Refer to the WPScan Vulnerability Report for advisory details.

Workarounds

  • Disable the social login functionality within UsersWP until the plugin can be updated
  • Enforce multi-factor authentication for administrator accounts through a separate WordPress MFA plugin
  • Restrict access to the WordPress login and OAuth callback endpoints using IP allowlists or a web application firewall
bash
# Verify installed UsersWP plugin version using WP-CLI
wp plugin get userswp --field=version

# Update UsersWP to the patched release
wp plugin update userswp --version=1.5.10

# Temporarily deactivate the plugin if patching is not immediately possible
wp plugin deactivate userswp

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.