VYPR

User Session Synchronizer

by WordPress

Source repositories

CVEs (2)

  • CVE-2026-15341CriAug 15, 2026
    risk 0.64cvss 9.8epss 0.00

    The User Session Synchronizer plugin for WordPress is vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0. The `synchronize_session()` function, hooked on `init` and therefore executed on every request, performs no nonce,…

  • CVE-2025-32612HigApr 9, 2025
    risk 0.46cvss 7.1epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in rafasashi User Session Synchronizer user-session-synchronizer allows Stored XSS.This issue affects User Session Synchronizer: from n/a through <= 1.4.0.