CVE-2026-12981

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
Configurations

No configuration.

History

24 Jul 2026, 20:17

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

24 Jul 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-24 07:16

Updated : 2026-07-24 20:48


NVD link : CVE-2026-12981

Mitre link : CVE-2026-12981

CVE.ORG link : CVE-2026-12981


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management