What is CVE-2026-12586?
The Lenxel WP WordPress theme lacks authorization checks in its password reset action, only validating a CSRF nonce. This allows unauthenticated attackers to reset any user's password (including admins) and take over the account. Immediate theme update is required to fix this critical vulnerability.
Azərbaycanca: Lenxel WP WordPress teması parol sıfırlama əməliyyatında yetkiləndirmə yoxlaması aparmır, yalnız CSRF nonce-i yoxlayır. Bu, autentifikasiya olunmamış hücumçulara istənilən istifadəçinin (admin daxil) parolunu sıfırlayıb hesabı ələ keçirməyə imkan verir. Təhlükəsizliyi təmin etmək üçün tema dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
How can unauthenticated attackers exploit the password reset function in the Lenxel WP WordPress theme?
The theme does not verify if a user is logged in during the password reset action, only validating a CSRF nonce. Therefore, unauthenticated attackers can reset the password of any user, including admins, and take over the account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.