THREAT OPS › Threat News › [NVD] CVE-2026-18052 — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the sit
[NVD] CVE-2026-18052 — The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the sit
CVE-2026-18052 CVSS: None Published: 2026-08-22T06:16:15.647
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
Indicators of compromise
- CVE-2026-18052cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18052