CVE-2026-12417Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_password()` AJAX handler — registered via `wp_ajax_nopriv_pravel_change_password` and therefore accessible to unauthenticated users — performing no nonce verification, no capability check, and only a loose equality check between an attacker-supplied `reset_activation_code` POST parameter and the target user's `forgot_email` user meta value; when a user has never initiated a password reset, `get_user_meta()` returns an empty string that trivially satisfies this check against an omitted or empty attacker-supplied code. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by sending a crafted POST request to `admin-ajax.php` with `action=pravel_change_password`, `reset_user_id` set to the target account's user ID, and `new_password_custom` set to an attacker-chosen password. Successful exploitation allows the attacker to authenticate with the newly set password and fully take over the targeted account, achieving administrator-level privilege escalation on the affected site.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-06-24); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-06-24: 3Mentions · 2026-06-25: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-07-18: 1PoC Mentioned / Linked · 2026-06-25: 1PoC Mentioned / Linked · 2026-06-27: 1Active Exploitation · 2026-06-27: 1Patch / Workaround · 2026-06-24: 2Technical Details · 2026-06-24: 3Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-07-18: 106-2406-2506-2706-2807-18
Signal classification5 categories
Disclosure
228.6%
Patch
228.6%
PoC
114.3%
Active Exploitation
114.3%
General
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-243
Disclosure1Patch2
2026-06-251
PoC1
2026-06-271
Active Exploitation1
2026-06-281
Disclosure1
2026-07-181
General1
Full discourse7 posts
  • ExploitGrid@exploitgrid
    Active Exploitation

    Top CVEs w/ public exploits (Jun 20–27): CVE-2026-48908 Joomla SPB RCE (exploited live) CVE-2026-48909 Joomla SP LMS PHP Obj injection CVE-2026-12417 SignUp/In admin takeover CVE-2026-12416 Invoice Generator takeover CVE-2026-39938 Cacti LFI Protect via http://exploitgrid.net

    Post summary

    The post highlights multiple CVEs that have public exploits, one of which is confirmed to be actively exploited in the wild, but no detailed exploit code or patch is provided.

    2502191.9K
    33 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-12417: SignUp & SignIn WordPress Plugin Authentication Bypass - What It Means for Your Business and How to Respond https://hubs.li/Q04pY-kj0

    Post summary

    The snippet provides only a title and link, offering minimal technical detail and no evidence of PoC, exploits, or patches.

    1001096
    32 followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-12417 — CVSS 9.8/10 ██████████ The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/IlFRSvwpjL

    Post summary

    A critical authentication‑bypass flaw (CVE‑2026‑12417) in the WordPress SignUp & SignIn plugin is highlighted, and the tweet urges users to apply the available patch immediately; no exploit or active usage is reported.

    1000169
    59 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - WordPress SignUp SignIn auth bypass via unauthenticated password reset (CVE-2026-12417) The SignUp SignIn WordPress plugin contains an authentication bypass in its unauthenticated AJAX handler pravel_change_password that allows password resets without proper authorization. The root cause is missing nonce/capability checks combined with improper input validation and weak/loose comparison logic against user meta, enabling the reset condition to be trivially satisfied. An attacker can exploit this remotely by sending a crafted request to /wp-admin/admin-ajax.php with no login required, targeting any username/user ID including administrators. Successful exploitation enables arbitrary password reset, full account takeover, and likely full site compromise (admin access, plugin/theme changes, data theft, malware injection). 👉 Affected: SignUp SignIn WordPress plugin <= 1.0.0 | Upgrade to No fix yet - treat as suspicious

    Post summary

    An unauthenticated authentication bypass in the SignUp SignIn WordPress plugin allows attackers to reset passwords and take over admin accounts; no patch is available yet.

    01010163
    226 followersView on X
  • SecAlerts@SecAlertsCo
    Disclosure

    CVE-2026-12417: WordPress "SignUp &amp; SignIn" plugin (≤1.0.0) has a critical 9.8 flaw. Weak password reset validation lets unauthenticated attackers take over any account via a bruteforceable reset_activation_code. #WordPress #cybersecurity https://secalerts.co/vulnerability/CVE-2026-12417?utm_campaign=x https://t.co/A29NOnnKgl

    Post summary

    The tweet discloses a critical flaw (CVSS 9.8) in the WordPress SignUp & SignIn plugin, detailing the vulnerability mechanics but offering no PoC, exploit code, or patch information.

    0000087
    846 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-12417-signup-signin-version-1-0-0-critical-vulnerability-proof-of-concept CVE-2026-12417 signup-signin (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomiced

    Post summary

    A proof-of-concept for CVE-2026-12417 affecting the signup-signin WordPress plugin has been published, highlighting a critical vulnerability with a CVSS score of 9.8, without any evidence of active exploitation or remediation guidance.

    0000048
    11 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 CRITICAL: CVE-2026-12417 (CVSS 9.8) SignUp &amp; SignIn WordPress plugin ≤1.0.0 allows unauthenticated attackers to bypass authentication &amp; takeover ANY account including admins via weak password reset validation. Patch immediately! #CVE #PatchNow #WordPress https://t.co/k8CcXEmkDJ

    Post summary

    CVE-2026-12417 permits unauthenticated attackers to bypass authentication and take over any account in the SignUp & SignIn WordPress plugin, so immediate patching is required.

    0000042
    50 followersView on X

Explore more