SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14836

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-01 · Last synced 2026-08-31

CyberRota Analysis

AI-Generated

The Login & Register Forms WordPress plugin prior to version 3.2.5 is vulnerable due to inadequate enforcement of rate limits on its password-reset verification-code process, allowing unauthenticated attackers to manipulate the attempt counter. This flaw enables attackers to brute-force the verification code, potentially leading to account takeovers, including administrative accounts, when the reset mode is active. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-14836
Severity
HIGH
CVSS
8.1
EPSS
0.23%
WordPress

Original NVD Description

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.