CVE

CVE-2026-18469 — Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-18469 Login & Register Forms – Popup, Slider, Profile & WooCommerce [easy-login-woocommerce] < 4.0.2 Improper Authentication Unknown < 4.0.2 4.0.2 2026-08-10

CVE-2026-18469

The WordPress plugin "Login & Register Forms" before version 4.0.2 fails to properly enforce a password reset attempt limit, allowing an attacker to reset the limit and brute-force a verification code to gain unauthorized access to any account, including administrator accounts. This vulnerability is particularly concerning because it can be exploited by unauthenticated attackers, making it easier for them to gain control of a website. The issue arises from the plugin's reliance on client-controlled data to verify the verification code and track attempt counts.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.