PT-2026-67014 · WordPress · Lenxel Wp
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Lenxel WP versions prior to 1.0.32
Description
The password-reset action in the Lenxel WP WordPress theme fails to perform authorization or ownership checks, validating only a CSRF (Cross-Site Request Forgery) nonce. This allows unauthenticated attackers to reset the password of any user, including administrators, leading to full account takeover.
Recommendations
Update Lenxel WP to version 1.0.32 or later.
Exploit
Fix
CSRF
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lenxel Wp