CVE-2026-16300

CRITICAL

Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset

Title source: cna
STIX 2.1

Description

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/0508f8c8-8ecc-4982-b14c-bf5f1c3d1c8f/

Scores

CVSS v3 9.8
EPSS 0.0030
EPSS Percentile 22.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Products (1)
None/ChamaWP < 1.0.13
Published Aug 03, 2026
Tracked Since Aug 03, 2026