Feed/CVE-2026-12586
CVE-2026-12586HIGHCVSS 8.1

CVE-2026-12586

Published Aug 2, 2026·Updated Aug 4, 2026

NVD Description

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free