


Perceptive Security
SOC/SIEM Consultancy

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arb…
Published:
3 augustus 2026 om 00:00:00
Alert date:
3 augustus 2026 om 20:04:46
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The ChamaWP WordPress plugin versions before 1.0.13 contains a critical vulnerability in its password reset functionality. The plugin fails to properly validate password reset requests, allowing unauthenticated attackers to reset passwords for arbitrary users. This includes administrator accounts, making the flaw particularly severe. Successful exploitation could lead to a complete site takeover. No authentication is required to exploit this vulnerability. The issue has been addressed in version 1.0.13 of the plugin. WordPress site administrators using affected versions should update immediately to mitigate risk.
Technical details
Mitigation steps:
Affected products:
ChamaWP WordPress Plugin before 1.0.13
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-16300
https://wpscan.com/vulnerability/0508f8c8-8ecc-4982-b14c-bf5f1c3d1c8f/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
