A vulnerability classified as critical has been found in rafasashi User Session Synchronizer Plugin up to 1.4.0 on WordPress. This vulnerability affects the function synchronize_session. This manipulation of the argument ussync-key/ussync-token/ussync-ref causes improper authentication.

This vulnerability is handled as CVE-2026-15341. The attack can be initiated remotely. There is not any exploit available.