
Login links without identity binding are replayable tokens, not auth. CVE-2026-18052 in ManageWP Worker. https://radar.offseq.com/threat/cve-2026-18052-cwe-287-improper-authentication-in-managewp-worker-08445d8d9fb49f79
Post summary
The text briefly discloses a vulnerability (CVE‑2026‑18052) in ManageWP Worker, noting that login links lack proper identity binding and are replayable tokens, classified as improper authentication.


