CVE-2026-15341
Description
The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The synchronize_session() function, hooked on init and therefore executed on every request, performs no nonce, capability, or shared-secret validation against the attacker-supplied ussync-key, ussync-token, and ussync-ref parameters; when ussync-key references an unregistered slot, get_option() returns false for both the secret key and the domain list, causing the AES-256-CBC encryption key to degrade to the fully predictable md5('') and the referer allowlist to collapse to an empty-string match, while the AES IV is unconditionally hard-coded as md5('another-secret'). This makes it possible for unauthenticated attackers to supply a crafted request encrypting any known or guessable user email address in the ussync-ref parameter, causing the handler to call wp_set_auth_cookie() for the matched user and granting full authentication as that user — including administrators — with no prior knowledge of site secrets.
Affected products
1- Range: <=1.4.0
Patches
Vulnerability mechanics
References
7- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- plugins.trac.wordpress.org/browser/user-session-synchronizer/tags/1.4.0/includes/class-user-session-synchronizer.phpnvd
- www.wordfence.com/threat-intel/vulnerabilities/id/cbc32e6d-47c5-4050-ba77-5a54203fe56anvd
News mentions
0No linked articles in our index yet.