← WordPress Vulnerabilities
WordPress security by component

SignUp & SignIn

SignUp & SignIn is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jun 24, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: signup-signin

CVE-2026-12417: SignUp & SignIn: Privilege escalation or authentication bypass

SignUp & SignIn is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.0.0.

PublishedJun 24, 2026
Known safe version> 1.0.0
Safe version
Jun 24, 2026 CVE-2026-12417
SignUp & SignIn: Privilege escalation or authentication bypass
SignUp & SignIn is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 1.0.0.
> 1.0.0
CVE9.8
NVDPending