Skip to content
Latest alertgo-ethereum v1.17.8 security release fixes p2p DoS issues and a STUN-response node crash
0xCERT
All advisories
High0xCERT-2026-0179·

CVE-2026-19125: The EthPress – Web3 Login plugin for WordPress

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executing, causing unconditional fall-through to the login block where Address::log_in() calls wp_set_auth_cookie() regardless of whether the submitted signature is valid. This makes it possible for unauthe…

Vuln-watch · relayed from the NVD / CVE program; see Source & attribution below

Affected chainsEthereum

Summary

The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.3.5. This is due to the verify_login() function in app/Login.php containing a missing return statement in the signature verification failure branch — when Signature::verify2() reports a mismatch, the function only assigns a WP_Error to a local variable and continues executing, causing unconditional fall-through to the login block where Address::log_in() calls wp_set_auth_cookie() regardless of whether the submitted signature is valid. This makes it possible for unauthenticated attackers to log in as any WordPress user who has a linked wallet address — including administrators — by submitting that user's public wallet address alongside an arbitrary well-formed signature, enabling full site takeover.

Severity

High (CVSS 8.1), as scored by NVD.

Weakness

  • CWE-287

Recommended actions

  • Check whether you run or depend on the affected component and version
  • Apply the vendor's fix or mitigation from the references below

Source & attribution

This 0xCERT advisory summarises CVE-2026-19125 from the U.S. National Vulnerability Database: https://nvd.nist.gov/vuln/detail/CVE-2026-19125. Details may change; refer to the original source for the authoritative record.

OpenPGP-signed. The signed text of this advisory verifies against the 0xCERT key CCC7 D9EC 9415 723D.

Published 2026-09-23 · last updated 2026-10-08

curl -s https://www.0xcert.com/pgp.asc | gpg --import && curl -s https://www.0xcert.com/advisory/0xCERT-2026-0179/signed.txt | gpg --verify