What is CVE-2026-12981?
The CAFEHAUS API WordPress plugin up to version 1.0.0 lacks authentication and authorization when updating user passwords. This allows unauthenticated attackers to reset the password of any user, including administrators, leading to full account takeover. Immediate patching or plugin deactivation is recommended.
Azərbaycanca: CAFEHAUS API WordPress plaginində (1.0.0 versiyasına qədər) autentifikasiya və avtorizasiya çatışmazlığı mövcuddur. Bu boşluq sayəsində autentifikasiya olunmamış hücumçular istənilən istifadəçinin, o cümlədən adminlərin şifrəsini dəyişərək hesabları tam ələ keçirə bilər. Dərhal plagini yeniləmək və ya söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the CAFEHAUS API plugin are affected by CVE-2026-12981?
This vulnerability affects all versions of the CAFEHAUS API WordPress plugin up to version 1.0.0.
What can an unauthenticated attacker do by exploiting CVE-2026-12981?
Unauthenticated attackers can reset the password of any user, including administrators, leading to full account takeover.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.