Vulnerability Description
The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, allowing attackers who obtain such a link to gain a session as any user on the site, including an administrator.
References
FAQ
What is CVE-2026-18052?
CVE-2026-18052 is a documented vulnerability. The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent an already used login link from being replayed, al...
How severe is CVE-2026-18052?
CVSS scoring is not yet available for CVE-2026-18052. Check NVD for updates.
Is there a patch for CVE-2026-18052?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.