WordPress Plugin Vulnerabilities

Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass

Description

The plugin does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Chamseddine Bouzaiene
Submitter
Chamseddine Bouzaiene
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-17 (about 1 month ago)
Added
2026-07-17 (about 1 month ago)
Last Updated
2026-08-21 (about 3 days ago)

Other