SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12586

HIGH · CVSS 8.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

The Lenxel WP WordPress theme versions up to 1.0.31 lack proper authorization checks during the password-reset process, relying solely on a CSRF nonce for validation. This vulnerability enables unauthenticated attackers to reset passwords for any user account, including those of administrators, potentially leading to account takeover. WordPress site administrators using this theme should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-12586
Severity
HIGH
CVSS
8.1
EPSS
0.17%
WordPress

Original NVD Description

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.