
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1729 is an authentication bypass vulnerability in the AdForest theme for WordPress, affecting all versions up to and including 6.0.12. The flaw allows unauthenticated attackers to log in as arbitrary users, including administrators, by exploiting improper identity verification in the sb_login_user_with_otp_fun function. It was published on February 12, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly, Red Hat CVE).
The root cause is classified as CWE-306 (Missing Authentication for Critical Function): the AdForest theme's OTP-based login function sb_login_user_with_otp_fun does not properly verify a user's identity before authenticating them, allowing the authentication step to be bypassed entirely. An unauthenticated remote attacker can send a crafted network request to trigger this function and authenticate as any user — including site administrators — without supplying valid credentials or a valid OTP. No privileges or user interaction are required, and the attack vector is fully network-accessible (Feedly). A public proof-of-concept exploit is available on GitHub (PoC GitHub).
Successful exploitation grants an attacker full administrative access to the affected WordPress installation, enabling complete compromise of confidentiality, integrity, and availability. An attacker could steal sensitive user and site data, inject malware or backdoors, deface the website, install malicious plugins, or use the compromised site as a pivot point for further attacks against site visitors or connected infrastructure (Feedly).
A public proof-of-concept exploit was published on GitHub on February 12, 2026, shortly after the CVE was disclosed (PoC GitHub). As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and no threat actor attribution has been made. The EPSS score is approximately 0.222%, reflecting a currently low but non-negligible probability of exploitation. The vulnerability is detectable by Qualys (detection ID 530945) and has not been added to the CISA KEV catalog (Feedly, Qualys).
sb_login_user_with_otp_fun function, typically accessible without authentication via WordPress's wp-ajax.php or a custom route.admin) without a valid OTP or with a manipulated/empty OTP value, exploiting the missing identity verification logic.wp-admin/admin-ajax.php) with action parameters referencing sb_login_user_with_otp_fun; repeated login attempts for high-privilege accounts (e.g., admin) from unexpected IP addresses.wp_users.As of the disclosure date, no official patch has been released for the AdForest theme. Recommended immediate mitigations include: (1) disabling or removing the AdForest theme from affected WordPress installations; (2) implementing WAF rules to block requests invoking the sb_login_user_with_otp_fun function; (3) restricting access to WordPress login and AJAX endpoints at the network or server level; (4) monitoring authentication logs for suspicious login activity; and (5) applying the patch immediately once the theme vendor releases an updated version beyond 6.0.12 (Feedly, Wordfence).
Wordfence included CVE-2026-1729 in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as a critical authentication bypass (Wordfence). The vulnerability was discussed on Mastodon by security community accounts and noted in PoC-week roundups (tonyharris.io). Security researchers at Infinit Security published a dedicated write-up shortly after disclosure (Infinit Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."