top of page
perceptive_background_267k.jpg

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arb…

Published:

3 August 2026 at 00:00:00

Alert date:

3 August 2026 at 20:04:46

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The ChamaWP WordPress plugin versions before 1.0.13 contains a critical vulnerability in its password reset functionality. The plugin fails to properly validate password reset requests, allowing unauthenticated attackers to reset passwords for arbitrary users. This includes administrator accounts, making the flaw particularly severe. Successful exploitation could lead to a complete site takeover. No authentication is required to exploit this vulnerability. The issue has been addressed in version 1.0.13 of the plugin. WordPress site administrators using affected versions should update immediately to mitigate risk.

Technical details

Mitigation steps:

Affected products:

ChamaWP WordPress Plugin before 1.0.13

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page