CRITICAL
9.8 CVE-2026-16259 Published 29 Aug 2026
WordPress Uix UserCenter Plugin Account Takeover
Worried this affects one of your servers?
The Uix UserCenter WordPress plugin, up to version 1.0.3, has a critical security flaw. It does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester.
This allows unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.
Reference: CVE-2026-16259 on NVD
← Back to Security News