CVE-2026-19125 is an authentication-bypass vulnerability in the EthPress – Web3 Login plugin for WordPress through version 2.3.5. The signature-verification failure path in the verify_login() function fails to return after Signature::verify2() identifies a mismatch. Although the function creates a WP_Error, execution continues into the login path, where Address::log_in() sets the WordPress authentication cookie without enforcing successful signature verification. An unauthenticated attacker can authenticate as a WordPress account associated with a wallet address by supplying that account's public wallet address and an arbitrary well-formed signature.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This three-file repository contains a standalone Python proof of concept, a detailed README, and a source patch showing the vulnerable-to-fixed change in EthPress. `poc.py` is the sole executable entry point and implements Ethereum cryptographic operations internally, requiring only the Python `requests` package. It accepts individual URLs or target files, one or more wallet addresses, configurable concurrency and TLS behavior, and writes JSON Lines results. The exploit targets CVE-2026-19125 in EthPress `Login::verify_login()`. In vulnerable releases, a failed `Signature::verify2()` result creates a `WP_Error` but does not stop processing. Execution reaches the login path, constructs an `Address` from the user-controlled `coinbase` wallet address, and invokes the WordPress login/registration logic. The PoC fetches the public login nonce, signs using an unrelated attacker-generated Ethereum key (or retries using an empty signature), submits the selected victim address, retains the returned WordPress cookie, and verifies the resulting identity and privileges. This is an active authentication-bypass/account-takeover exploit rather than a detection-only script. `patch.diff` shows the remedial change in EthPress 2.3.6: the address login block is wrapped in `if ($verified)`, and failed verification explicitly leaves the request as an error. The README documents expected behavior for linked and unlinked addresses, patched controls, and registration-enabled installations. Although the README references additional lab artifacts, scripts, and evidence files, those referenced files are not present in the analyzed archive.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability in EthPress – Web3 Login for WordPress through version 2.3.5. An unauthenticated attacker can submit a target user's linked public wallet address with an arbitrary well-formed signature and authenticate as that user, including an administrator, enabling full site takeover.
An authentication-bypass vulnerability in the EthPress – Web3 Login WordPress plugin through version 2.3.5. Failed wallet-signature verification falls through to the login path, allowing an unauthenticated attacker to authenticate as any user with a linked wallet address, potentially including an administrator, using that public address and an arbitrary well-formed signature. Successful exploitation can result in full site takeover.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.