All verified exploits

CVE-2026-5130 Unauthenticated Admin Takeover via Cookie Forgery

Deterministic critical WordPress Added cve-verified-cve-2026-5130

Detects WordPress instances running the Debugger & Troubleshooter plugin version 1.3.2 or earlier, where the User Role Simulator feature accepts a raw user ID from the wp_debug_troubleshoot_simulate_user cookie without any cryptographic validation. An unauthenticated attacker sets this cookie to 1 (the default admin account) to gain full administrator access. The fix in 1.4.0 replaces the raw ID with a cryptographically signed token that requires database-backed validation.

Related WordPress exploits

Is your app exploitable through CVE-2026-5130?

Scan your domain free