CRITICAL 9.1 CVE-2026-91995 Published 15 Sept 2026

WordPress Pig Plugin Auth Bypass

Worried this affects one of your servers?

WordPress Pig plugin before version 4.1.0 has a serious authentication bypass vulnerability.

In the /register/password endpoint, password verification results are ignored, allowing any value to be set as the current password.

Remote attackers can exploit this by submitting a username with an incorrect current password, effectively overwriting any account credentials, including the admin account, and gaining full administrative control.

Reference: CVE-2026-91995 on NVD

← Back to Security News