WORDPRESS · AUGUST 2026 · EARLY WARNING

User Session Synchronizer WordPress Plugin Vulnerable to Authentication Bypass

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected component
user session synchronizer plugin (wordpress)
Patched version
Not yet available
CVE-2026-15341

The User Session Synchronizer plugin for WordPress is reportedly vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0.

What happened

The User Session Synchronizer plugin for WordPress is under investigation for a critical vulnerability that allows unauthenticated attackers to bypass authentication and take over accounts, including administrator accounts. This is due to the `synchronize_session()` function, which is executed on every request, failing to validate attacker-supplied parameters. When a specific parameter references an unregistered slot, the encryption key degrades to a predictable value, and the referer allowlist collapses to an empty-string match. This vulnerability affects all versions up to, and including, 1.4.0.

To assess your exposure, check if your WordPress site uses the User Session Synchronizer plugin and verify the version. If you are using version 1.4.0 or earlier, you are potentially affected. It is crucial to review your site access logs for any suspicious activity that may indicate an attempted or successful exploit.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If user session synchronizer plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are potentially affected if your WordPress site uses the User Session Synchronizer plugin and the version is 1.4.0 or earlier.

What should I do right now?

Check the version of the plugin on your site. If you are using version 1.4.0 or earlier, upgrade to a version beyond 1.4.0 once it becomes available and review your site access logs for any suspicious activity.

Is there a patched version available?

No official fix has been published yet. Monitor the primary sources for updates on a patched version.

What is the severity of this vulnerability?

The severity of this vulnerability is CRITICAL with a CVSS score of 9.8.

Sources

Join the 0Day waitlist →

← Back to all threats