CVE-2026-18468
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or
CVSS
—
No CVSS
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 10, 2026 · Last modified: Aug 10, 2026
Not enough EPSS history yet.
The Login & Register Forms WordPress plugin before 4.0.2 does not bind the password reset verification state to the account being reset or to the party that completed the verification, keying it instead on a value the client controls, allowing unauthenticated attackers to take over the account of any user who recently completed a reset verification, including an administrator.
No related CVEs by CWE or product.