CyberSec.Space Logo
返回 CVE 浏览器

CVE-2026-12981

HIGH
7.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2026-07-24
Last Modified2026-07-24
Data SourcesNVD

Vulnerability Description

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

Affected Platforms (CPE)

No CPE configurations currently published for this record.

References & Advisories

相关漏洞威胁