CRITICAL
9.8 CVE-2026-86709 Published 17 Sept 2026
Pressengine WordPress Plugin Unauthenticated Login Bypass
Worried this affects your website?
The Pressengine WordPress plugin, version 1.0 and earlier, contains a critical security vulnerability. The login handler does not properly validate credentials, allowing unauthenticated attackers to log in as any user, including administrators, by simply issuing a session request.
This vulnerability can be exploited by attackers to gain unauthorized access to websites running the affected Pressengine plugin, potentially leading to data theft or website defacement.
Reference: CVE-2026-86709 on NVD
← Back to Security News