CyberSec.Space Logo
CVEブラウザに戻る

CVE-2026-12981

HIGH
7.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-24
Last Modified2026-07-24
Data SourcesNVD

Vulnerability Description

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

関連する脆弱性情報