CVE-2026-18468
The Login & Register Forms WordPress plugin has a vulnerability that allows an attacker to take control of any user's account, including an administrator's, if that user had recently completed a password reset verification. This is because the plugin does not properly link the verification state to the specific user account being reset, instead relying on a value controlled by the client, which can be manipulated by an attacker. As a result, an attacker can gain unauthorized access to any user's account that has recently completed a password reset.
Based on public CVE data (MITRE/NVD).