PT-2026-67110 · WordPress · Chamawp

·

CVE-2026-16300

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ChamaWP versions prior to 1.0.13
Description Insufficient validation of password reset requests allows unauthenticated attackers to reset passwords for any user, including those with administrator privileges. This flaw can result in a complete takeover of the website.
Recommendations Update to version 1.0.13 or later.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16300

Affected Products

Chamawp