CVE-2026-12981
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Jul 24, 2026
Vendor
unknown
Description
The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.