
CVE-2026-5617 The Login as User plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. This is due to the handle_return_to_admin() fu… https://www.cve.org/CVERecord?id=CVE-2026-5617
Post summary
CVE-2026-5617 exposes a privilege‑escalation flaw in WordPress Login as User plugin versions up to 1.0.3, due to a bug in handle_return_to_admin(), with no mention of exploitation, fixes, or PoC.
