CRITICAL 9.8 CVE-2026-16259 Published 29 Aug 2026

WordPress Uix UserCenter Plugin Account Takeover

Worried this affects one of your servers?

The Uix UserCenter WordPress plugin, up to version 1.0.3, has a critical security flaw. It does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester.

This allows unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.

Reference: CVE-2026-16259 on NVD

← Back to Security News