CVE-2026-5722
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-5722 is a critical Authentication Bypass vulnerability in the MoreConvert Pro plugin for WordPress, affecting all versions up to and including 1.9.14. The flaw resides in the guest waitlist verification flow, which fails to invalidate or regenerate verification tokens when a customer's email address is changed, enabling unauthenticated attackers to authenticate as any existing user, including administrators. It was published on May 5, 2026, with Wordfence credited as the assigner. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Wordfence).

Technical details

The root cause is classified as CWE-287 (Improper Authentication): the plugin's guest waitlist verification flow issues a one-time verification token tied to an email address but does not invalidate that token when the associated email is subsequently changed via the public waitlist interface. An unauthenticated attacker can exploit this by first registering a guest waitlist entry with an attacker-controlled email to obtain a valid verification token, then modifying the guest customer's email to match a target account (e.g., an administrator), and finally replaying the original verification link to authenticate as that target user. The attack requires no privileges and no user interaction, and is fully remotely exploitable over the network (GitHub Advisory, Wordfence).

Impact

Successful exploitation grants an unauthenticated attacker full authentication as any WordPress user, including site administrators, on affected installations. This enables complete site compromise: attackers can modify content, install malicious plugins or themes, exfiltrate sensitive user and business data, create backdoor accounts, or fully take over the WordPress installation. The high confidentiality, integrity, and availability impacts reflect the potential for total loss of control over the affected site (GitHub Advisory, Wordfence).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.24–0.45%, placing it in roughly the 64th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the MoreConvert Pro plugin (versions ≤ 1.9.14) by scanning for the plugin's presence via common WordPress plugin enumeration techniques (e.g., checking /wp-content/plugins/smart-wishlist-for-more-convert/).
  2. Obtain a guest verification token: Register a guest waitlist entry using an attacker-controlled email address through the plugin's public waitlist form. Receive the verification email containing a valid verification token/link.
  3. Change the guest email to the target: Using the plugin's public waitlist guest management flow, update the guest customer's email address from the attacker-controlled address to the email address of the target account (e.g., a known administrator email).
  4. Replay the original verification link: Submit or visit the original verification link/token obtained in step 2. Because the plugin does not invalidate the token upon email change, the token remains valid and now authenticates the request as the target user (administrator).
  5. Achieve full access: Upon successful token verification, the attacker is authenticated as the target WordPress user, gaining full administrative access to the site, enabling further malicious actions such as installing backdoors, exfiltrating data, or creating persistent admin accounts (GitHub Advisory, Wordfence).

Indicators of compromise

  • Network: Repeated or unusual POST/GET requests to the MoreConvert Pro waitlist endpoints (e.g., paths associated with /smart-wishlist-for-more-convert/) from a single IP, particularly requests that update guest email addresses followed immediately by verification link submissions.
  • Logs: WordPress access logs showing rapid sequential requests: (1) guest waitlist registration, (2) guest email update, and (3) verification link access — all from the same IP or session, especially targeting administrator email addresses.
  • Logs: WordPress authentication logs (wp-login.php or equivalent) showing unexpected logins for administrator accounts from unfamiliar IP addresses or at unusual times.
  • File System: Newly installed plugins, themes, or PHP files in the WordPress directory not authorized by site administrators; presence of web shells in upload directories.
  • WordPress Admin: Unexpected new administrator accounts created, or changes to existing administrator email addresses or passwords shortly after suspicious waitlist activity.

Mitigation and workarounds

At the time of initial disclosure, no official patch was confirmed available for MoreConvert Pro beyond version 1.9.14; users should check the MoreConvert changelog for updated releases and apply any available update immediately. As an interim workaround, site administrators should disable the MoreConvert Pro plugin until a patched version is confirmed. Additional compensating controls include restricting access to the plugin's public waitlist functionality (e.g., via WAF rules or IP allowlisting), enabling two-factor authentication on all WordPress administrator accounts, and monitoring for unauthorized administrative logins or suspicious account activity (Wordfence, GitHub Advisory).

Community reactions

Wordfence, the vulnerability's assigner, included CVE-2026-5722 in its weekly WordPress vulnerability reports for both the May 4–10 and May 11–17, 2026 periods, highlighting it as a critical finding for WordPress site operators (Wordfence Weekly Report). The vulnerability was also noted on Mastodon security channels and by the offseq threat radar shortly after disclosure, reflecting moderate community awareness. No major vendor statements beyond Wordfence's advisory or significant mainstream media coverage have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92541HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-92540HIGH7.2
  • import-users-from-csv-with-meta
NoYesSep 20, 2026
CVE-2026-86785MEDIUM5.3
  • woo-to-facebook-shop
NoNoSep 20, 2026
CVE-2026-92965LOW3.7
  • tiktok-for-business
NoYesSep 20, 2026
CVE-2026-92423LOW2.7
  • meow-gallery
NoYesSep 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management