CVE-2026-12586
N/A
N/A
Summary
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Lenxel WP | 0 <= 1.0.31 | affected |
Weaknesses
- CWE-287 Improper Authentication
- CWE-352 Cross-Site Request Forgery (CSRF)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.