What is CVE-2026-14309?
This CVE identifies a vulnerability in the "Chat On Desk Order Notifications" WordPress plugin versions before 1.0.9, where the password reset function fails to verify the one-time password (OTP) before processing the request. This allows unauthenticated attackers to reset passwords for arbitrary users, including administrators, and take over their accounts. Immediate update to version 1.0.9 or later is strongly recommended.
Azərbaycanca: Bu CVE, WordPress üçün "Chat On Desk Order Notifications" plaqininin 1.0.9-dan əvvəlki versiyalarında parol sıfırlama funksiyasında boşluq olduğunu göstərir. Təcavüzkar, birdəfəlik şifrənin (OTP) yoxlanılmaması səbəbindən autentifikasiya olmadan istənilən istifadəçinin, o cümlədən administratorun parolunu sıfırlaya və hesabı ələ keçirə bilər. Plaqini dərhal 1.0.9 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which WordPress plugin is affected by CVE-2026-14309?
This vulnerability affects the "Chat On Desk Order Notifications" plugin versions before 1.0.9.
What can an unauthenticated attacker do by exploiting CVE-2026-14309?
Due to the failure to verify the OTP, an attacker can reset the password of any user, including administrators, and take over their accounts.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.