
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5722 is a critical Authentication Bypass vulnerability in the MoreConvert Pro plugin for WordPress, affecting all versions up to and including 1.9.14. The flaw resides in the guest waitlist verification flow, which fails to invalidate or regenerate verification tokens when a customer's email address is changed, enabling unauthenticated attackers to authenticate as any existing user, including administrators. It was published on May 5, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Wordfence).
The root cause is classified as CWE-287 (Improper Authentication): the plugin's guest waitlist verification flow issues a one-time verification token tied to an email address but does not invalidate that token when the associated email is subsequently changed via the public waitlist interface. An unauthenticated attacker can exploit this by first registering a guest waitlist entry with an attacker-controlled email to obtain a valid verification token, then modifying the guest customer's email to match a target account (e.g., an administrator), and finally replaying the original verification link to authenticate as that target user. The attack requires no privileges and no user interaction, and is fully remotely exploitable over the network (GitHub Advisory, Wordfence).
Successful exploitation grants an unauthenticated attacker full authentication as any WordPress user, including site administrators, on affected installations. This enables complete site compromise: attackers can modify content, install malicious plugins or themes, exfiltrate sensitive user and business data, create backdoor accounts, or fully take over the WordPress installation. The high confidentiality, integrity, and availability impacts reflect the potential for total loss of control over the affected site (GitHub Advisory, Wordfence).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.24–0.45%, placing it in roughly the 64th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time (GitHub Advisory).
/wp-content/plugins/smart-wishlist-for-more-convert/)./smart-wishlist-for-more-convert/) from a single IP, particularly requests that update guest email addresses followed immediately by verification link submissions.wp-login.php or equivalent) showing unexpected logins for administrator accounts from unfamiliar IP addresses or at unusual times.At the time of initial disclosure, no official patch was confirmed available for MoreConvert Pro beyond version 1.9.14; users should check the MoreConvert changelog for updated releases and apply any available update immediately. As an interim workaround, site administrators should disable the MoreConvert Pro plugin until a patched version is confirmed. Additional compensating controls include restricting access to the plugin's public waitlist functionality (e.g., via WAF rules or IP allowlisting), enabling two-factor authentication on all WordPress administrator accounts, and monitoring for unauthorized administrative logins or suspicious account activity (Wordfence, GitHub Advisory).
Wordfence, the vulnerability's assigner, included CVE-2026-5722 in its weekly WordPress vulnerability reports for both the May 4–10 and May 11–17, 2026 periods, highlighting it as a critical finding for WordPress site operators (Wordfence Weekly Report). The vulnerability was also noted on Mastodon security channels and by the offseq threat radar shortly after disclosure, reflecting moderate community awareness. No major vendor statements beyond Wordfence's advisory or significant mainstream media coverage have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."