The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 29 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-798

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.
Title Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-29T06:00:18.968Z

Reserved: 2026-07-20T08:29:53.101Z

Link: CVE-2026-16259

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-29T06:17:00.360

Modified: 2026-08-29T06:17:00.360

Link: CVE-2026-16259

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T09:45:04Z

Weaknesses