WordPress Plugin Vulnerabilities

Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass

Description

The plugin does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Chamseddine Bouzaiene
Submitter
Chamseddine Bouzaiene
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 16 days ago)
Added
2026-07-17 (about 15 days ago)
Last Updated
2026-07-31 (about 1 day ago)

Other