WordPress Plugin Vulnerabilities

Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation

Description

The plugin does not verify that the account being modified through an unauthenticated profile-update action belongs to the requester, and it authenticates that action with a token whose signing key is hardcoded and identical across every install, allowing unauthenticated attackers to forge a token for any user, overwrite an administrator's email and password, and take over the account.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-08-27 (about 2 days ago)
Added
2026-08-27 (about 1 day ago)
Last Updated
2026-08-27 (about 1 day ago)

Other