CVE-2026-1729Disclosure

MEDIUMCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the 'sb_login_user_with_otp_fun' function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 7 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 6 mentions (2026-02-12); latest day: 1
  • 7 total mentions across 2 days

Deep dive

Activity timeline7 mentions / 2d
02356Mentions · 2026-02-12: 6Mentions · 2026-02-23: 1PoC Mentioned / Linked · 2026-02-12: 1Exploit Tool / Code · 2026-02-12: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-23: 1Technical Details · 2026-02-12: 6Technical Details · 2026-02-23: 102-1202-23
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
Exploit
114.3%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-126
Disclosure4Exploit1Patch1
2026-02-231
Patch1
Full discourse7 posts
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: AdForest WordPress theme vuln (CVE-2026-1729) allows unauth'd admin logins via OTP bypass — all versions up to 6.0.12 at risk! Block the function & monitor access now. https://radar.offseq.com/threat/cve-2026-1729-cwe-306-missing-authentication-for-c-1533b53f #OffS... https://t.co/6SGWEBHkz1

    Post summary

    The tweet warns that CVE-2026-1729 permits unauthenticated admin logins via OTP bypass in AdForest theme up to v6.0.12, advising users to block the vulnerable function and monitor access.

    0001042
    268 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1729 Authentication Bypass Vulnerability in AdForest WordPress Theme Ve... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1729 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces the discovery of an authentication bypass flaw in the AdForest WordPress Theme, providing a link to the vulnerability details but offering no exploitation or mitigation specifics.

    0001032
    4.0K followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    Critical WordPress theme auth bypass (CVE-2026-1729)! The AdForest theme ≤ 6.0.12 fails to verify identity in its OTP login function, letting unauthenticated attackers log in as any user — even admins. Patch immediately, remove the theme if unpatched, and tighten login security. https://quttera.com/wordpress-malware-scanner #WordPress #CVE2026-1729 #WebSecurity #BotProtection

    Post summary

    AdForest theme versions ≤6.0.12 allow unauthenticated attackers to bypass authentication via OTP login, enabling them to log in as any user, including admins. Users should patch or remove the theme immediately and tighten login security.

    0000061
    37 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1729: CRITICAL] AdForest WordPress theme up to version 6.0.12 is prone to an authentication bypass flaw due to inadequate user identity verification, enabling unauthorized access and potential compro...#cve,CVE-2026-1729,#cybersecurity https://cvefind.com/CVE-2026-1729

    Post summary

    The advisory reports an authentication bypass flaw in AdForest WordPress theme up to version 6.0.12, allowing unauthorized access; no PoC, exploit code, active exploitation, or patch information is included.

    0000040
    583 followersView on X
  • _cr0w_@f3dscr0w
    Exploit

    🚨 f3ds cr3w did it first; again. CVE 9.8! In under 12 hours a writeup, working PoC exploit and readme for #vulnerable CVE-2026-1729 #Wordpress AdForest WordPress Authentication Bypass PoC. Sourcecode: https://github.com/ninjazan420/CVE-2026-1729-PoC-AdForest-WordPress-Authentication-Bypass Writeup: https://f3ds.vercel.app/posts/cve-2026-1729-adforest-wordpress-authentication-bypass/

    Post summary

    The post announces a working PoC exploit for CVE‑2026‑1729, a WordPress authentication bypass, and provides source code and a writeup.

    0000089
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1729 The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 6.0.12. This is due to the plugin not properly verifying a… https://www.cve.org/CVERecord?id=CVE-2026-1729

    Post summary

    The AdForest WordPress theme is vulnerable to authentication bypass up to version 6.0.12 due to improper verification by the plugin. No patch, exploit, or PoC was provided in the text.

    00000112
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL: CVE-2026-1729 in AdForest WordPress theme lets attackers bypass authentication & log in as any user — including admin! No patch yet. Protect your site now. Details: https://radar.offseq.com/threat/cve-2026-1729-cwe-306-missing-authentication-for-c-1533b53f #OffSeq ... https://t.co/jicmPEk6Nv

    Post summary

    CVE‑2026‑1729 is a critical authentication bypass vulnerability in the AdForest WordPress theme that lets attackers log in as any user, including admin. No patch has been released yet, so site owners should protect their sites immediately.

    0000026
    268 followersView on X

Explore more