← לוח פגיעויות

CVE-2026-12981

גבוהה 7.5

תיאור (מקור, אנגלית)

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-24/7/2026
CWE
CWE-269

קישורים