Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-19125— EthPress <= 2.3.5 - Unauthenticated Authentication Bypass

Quick assessment

Affected
lynn999 EthPress – Web3 Login
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 EthPress – Web3 登录插件(EthPress – Web3 Login)在所有不超过 2.3.5 的版本中存在认证绕过漏洞。该漏洞源于 文件中的 函数在签名验证失败分支中缺少 return 语句。当 检测到签名不匹配时,该函数仅将错误信息赋值给局部变量 ,却未中断执行流程,导致代码无条件地继续执行后续登录逻辑块。在此过程中, 函数会无条件调用 设置用户认证 Cookie,无论提交的签名是否有效。 因此,未授权的攻击者可以通过提交任意目标用户(包括管理员账户)关联的钱包地址,并搭

CVSS 8.1 · High EPSS 0.64% · P48
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-19125

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
EthPress <= 2.3.5 - Unauthenticated Authentication Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executing, causing unconditional fall-through to the login block where Address::log_in() calls wp_set_auth_cookie() regardless of whether the submitted signature is valid. This makes it possible for unauthenticated attackers to log in as any WordPress user who has a linked wallet address — including administrators — by submitting that user's public wallet address alongside an arbitrary well-formed signature, enabling full site takeover.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lynn999 EthPress – Web3 Login 0 ~ 2.3.5 -

II. Public POCs for CVE-2026-19125

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19125

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-19125 (1)

Other References for CVE-2026-19125 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-19125

No comments yet


Leave a comment