{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ethpress--2.3.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["EthPress (\u003c 2.3.6)"],"_cs_severities":["high"],"_cs_tags":["wordpress","authentication-bypass","cve-2026-19125"],"_cs_type":"threat","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-19125 is an authentication bypass vulnerability affecting the EthPress WordPress plugin, versions 2.3.5 and earlier. The vulnerability exists within the plugin's wallet-based login mechanism, specifically in the \u003ccode\u003eAddress::log_in()\u003c/code\u003e function and related cryptographic signature verification logic. An unauthenticated attacker can exploit this by providing a malformed or empty signature, which the plugin fails to validate correctly.\u003c/p\u003e\n\u003cp\u003eBy supplying an Ethereum wallet address that is already linked to a target WordPress user's account, an attacker can trick the system into authenticating as that user, including accounts with administrative privileges. Once the session cookie is issued, the attacker gains full access to the WordPress site's administrative functions. The flaw was disclosed alongside a functional proof-of-concept (PoC) that automates nonce harvesting, authentication bypass, and session validation. Defenders should identify exposed WordPress instances running EthPress and prioritize upgrading to version 2.3.6 or later.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs an initial GET request to \u003ccode\u003e/wp-login.php\u003c/code\u003e to extract the \u003ccode\u003eethpressLoginWP.loginNonce\u003c/code\u003e from the site's HTML.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a request to the plugin's AJAX endpoint, supplying a target WordPress user's linked wallet address and an empty or malformed cryptographic signature.\u003c/li\u003e\n\u003cli\u003eThe plugin's \u003ccode\u003eAddress::log_in()\u003c/code\u003e function fails to properly verify the signature integrity but proceeds to resolve the wallet address to the corresponding \u003ccode\u003euid\u003c/code\u003e in the WordPress database.\u003c/li\u003e\n\u003cli\u003eThe plugin invokes \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e using the resolved \u003ccode\u003euid\u003c/code\u003e, granting the attacker a session cookie for the targeted user.\u003c/li\u003e\n\u003cli\u003eThe attacker uses the returned session cookie to browse to the WordPress administrative dashboard.\u003c/li\u003e\n\u003cli\u003eThe attacker leverages the session to access privileged areas, such as \u003ccode\u003e/wp/v2/users/me\u003c/code\u003e or other administrative REST API endpoints, confirming full site control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized administrative access to WordPress sites running the vulnerable EthPress plugin. This impact includes the potential for complete site compromise, data exfiltration, and the creation of additional persistence mechanisms, such as new administrative users or injected malicious code. The vulnerability is highly severe for any enterprise or individual using EthPress, as it leverages pre-existing wallet links to bypass standard authentication entirely.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the EthPress plugin to version 2.3.6 or newer immediately. There is no configuration-based workaround for this vulnerability.\u003c/li\u003e\n\u003cli\u003eAudit WordPress \u003ccode\u003ewp_usermeta\u003c/code\u003e tables for the \u003ccode\u003eethpress\u003c/code\u003e meta_key to identify which accounts have linked wallet addresses and prioritize securing these high-value targets.\u003c/li\u003e\n\u003cli\u003eImplement the following web server-level detection to identify exploitation attempts targeting the plugin's authentication endpoint.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T14:55:42Z","date_published":"2026-09-23T14:55:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ethpress-auth-bypass/","summary":"CVE-2026-19125 allows unauthenticated attackers to bypass authentication in the EthPress WordPress plugin (v2.3.5 and below) by supplying malformed signatures to impersonate any user with a linked Ethereum wallet.","title":"Authentication Bypass in EthPress WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-ethpress-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - EthPress (\u003c 2.3.6)","version":"https://jsonfeed.org/version/1.1"}