Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16259: Uix UserCenter plugin can let attackers hijack admin accounts

CVE-2026-16259 · published 5 days ago
Summary

The Uix UserCenter plugin for WordPress (through version 1.0.3) does not confirm that the person changing a profile actually owns that account, and it uses the same secret key for all installations. This lets anyone create a fake token and change an administrator's email and password, taking full control of the site. Update the plugin to a fixed version or replace it, then reset admin passwords and watch for any unexpected account changes.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown uix usercenter <= 1.0.3
Original advisory text
Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published29 Aug 2026
Updated2 Sep 2026
First seen29 Aug 2026
Sources
CVE-2026-16259 · MITRE
Monitor software like this
Free during beta