CVE-2026-12595Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability exists in the loginpress_on_discord_login() Discord OAuth callback handler, which accepts the email field returned by Discord's /users/@me endpoint without ever checking that the profile's verified flag is true, then directly maps that email to a local WordPress account via get_user_by('email', $profile['email']) and issues an authenticated session cookie via wp_set_auth_cookie(). This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by registering a Discord account configured with an unverified email address that matches the target user's registered WordPress email and completing the standard Discord OAuth flow.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-10: 2Technical Details · 2026-07-10: 207-10
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-12595 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. The vulnerability… https://www.cve.org/CVERecord?id=CVE-2026-12595

    Post summary

    The text announces that LoginPress Pro is vulnerable to an authentication bypass via unverified OAuth email in versions up to 6.2.3, but provides no PoC, exploit, or patch details.

    00000750
    57.8K followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: LoginPress Pro 3-CVE Cluster — CVSS 8.1 x3 CVE-2026-12595: OAuth auth bypass (unverified email) CVE-2026-12597: OAuth auth bypass (GitHub callback) CVE-2026-12598: OAuth auth bypass (Spotify addon) → http://threataft.com/articles/loginpress-pro-cve-2026-12595-12597-12598 #cybersecurity #infosec #WordPress

    Post summary

    Three OAuth authentication bypass CVEs for LoginPress Pro are disclosed, each rated CVSS 8.1; no exploit details, patches, or active exploitation information are provided.

    0000096
    34 followersView on X

Explore more