CVE-2026-12981

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-24 07:16

Updated : 2026-07-24 20:48


NVD link : CVE-2026-12981

Mitre link : CVE-2026-12981

CVE.ORG link : CVE-2026-12981


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management