PT-2026-67014 · WordPress · Lenxel Wp

·

CVE-2026-12586

·

Published

2026-08-02

·

Updated

2026-08-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Lenxel WP versions prior to 1.0.32
Description The password-reset action in the Lenxel WP WordPress theme fails to perform authorization or ownership checks, validating only a CSRF (Cross-Site Request Forgery) nonce. This allows unauthenticated attackers to reset the password of any user, including administrators, leading to full account takeover.
Recommendations Update Lenxel WP to version 1.0.32 or later.

Exploit

Fix

CSRF

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12586

Affected Products

Lenxel Wp