All verified exploits

CVE-2026-5617 Subscriber-to-Admin Takeover via Cookie Forgery

Deterministic high WordPress Added cve-verified-cve-2026-5617

Detects WordPress instances running the Login as User plugin (one-click-login-as-user) version 1.0.3 or earlier, where the handle_return_to_admin() function in includes/class-login-handler.php trusts a client-controlled oclaup_original_admin cookie and re-authenticates the browser as that user without verifying the cookie was minted during a legitimate admin → user switch. Any authenticated Subscriber can mint the required nonce, set the cookie to user ID 1 (default admin), and call admin-post.php?action=oclaup_return_to_admin to gain full administrator access. The plugin was closed on WordPress.org with no patched release — uninstall is the only mitigation.

Related WordPress exploits

Is your app exploitable through CVE-2026-5617?

Scan your domain free