CRITICAL 9.8 CVE-2026-86709 Published 17 Sept 2026

Pressengine WordPress Plugin Unauthenticated Login Bypass

Worried this affects your website?

The Pressengine WordPress plugin, version 1.0 and earlier, contains a critical security vulnerability. The login handler does not properly validate credentials, allowing unauthenticated attackers to log in as any user, including administrators, by simply issuing a session request.

This vulnerability can be exploited by attackers to gain unauthorized access to websites running the affected Pressengine plugin, potentially leading to data theft or website defacement.

Reference: CVE-2026-86709 on NVD

← Back to Security News