WordPress Plugin Vulnerabilities

Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset

Description

The plugin does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

Proof of Concept

Affects Plugins

Fixed in 1.0.13

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
moonge
Submitter
moonge
Verified
Yes

Timeline

Publicly Published
2026-07-24 (about 1 month ago)
Added
2026-07-24 (about 1 month ago)
Last Updated
2026-08-21 (about 2 days ago)

Other