All 2 CVE vulnerabilities found in User Session Synchronizer, with AI-generated Chinese analysis, references, and POCs.
Vendor: rafasashi
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-15341 | User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to Account Takeover via 'ussync-key', 'ussync-token', and 'ussync-ref' Parameters CWE-287 | 9.8 | Critical | 2026-08-15 |
| CVE-2025-32612 | WordPress User Session Synchronizer plugin <= 1.4.0 - CSRF to Stored XSS vulnerability CWE-352 | 7.1 | High | 2025-04-09 |
All 2 known CVE vulnerabilities affecting User Session Synchronizer with full Chinese analysis, references, and POCs where available.