What is CVE-2026-14836?
CVE-2026-14836 is a critical vulnerability in the 'Login & Register Forms' WordPress plugin before version 3.2.5. It fails to properly enforce rate limiting on the password-reset verification-code flow by keying the counter on an unauthenticated, client-controlled value, allowing attackers to bypass restrictions. Affected users should immediately update the plugin to version 3.2.5 or higher.
Azərbaycanca: CVE-2026-14836, 'Login & Register Forms' adlı WordPress plagininin 3.2.5-dən əvvəlki versiyalarında aşkar edilmiş kritik boşluqdur. Bu boşluq autentifikasiya olunmamış hücumçulara parol sıfırlama doğrulama kodunun axınındakı rate limit məhdudiyyətini keçməyə imkan verir, çünki sayğac müştəri tərəfindən idarə olunan dəyərə əsaslanır. Təsirə məruz qalan istifadəçilər dərhal plagini 3.2.5 və ya daha yuxarı versiyaya yeniləməlidirlər.
FAQ2
Which WordPress plugin is affected by the CVE-2026-14836 vulnerability?
CVE-2026-14836 is a critical vulnerability affecting the 'Login & Register Forms' plugin for WordPress in versions prior to 3.2.5.
What should users do to protect themselves from CVE-2026-14836?
Affected users should immediately update the 'Login & Register Forms' plugin to version 3.2.5 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.