Feed/CVE-2026-18470
CVE-2026-18470HIGHCVSS 7.5

CVE-2026-18470

Published Aug 10, 2026·Updated Aug 10, 2026

NVD Description

The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not adequately redact the address returned in its response, allowing unauthenticated users to obtain registered users' email addresses, including administrators'.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free