What is CVE-2026-16300?
CVE-2026-16300 is a critical vulnerability in the ChamaWP WordPress plugin where unauthenticated attackers can reset any user's password, including administrators, due to improper validation of password reset requests. This could lead to a full site takeover. Immediate update to version 1.0.13 or later is recommended.
Azərbaycanca: CVE-2026-16300 — ChamaWP WordPress plaqinində autentifikasiya olunmamış hücumçulara ixtiyari istifadəçi (o cümlədən admin) parolunu sıfırlamağa imkan verən kritik boşluqdur. Bu, saytın tam ələ keçirilməsinə səbəb ola bilər. Plaqini dərhal 1.0.13 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
What risk does CVE-2026-16300 pose in the ChamaWP plugin?
CVE-2026-16300 allows unauthenticated attackers to reset any user's password, including administrators, which can lead to a full site takeover.
To which version should ChamaWP be updated to protect against CVE-2026-16300?
The plugin should be immediately updated to version 1.0.13 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.