๐Ÿ” CVE Alert

CVE-2026-12586

HIGH 8.1

Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset

CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
2th

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.

Vendor unknown
Product lenxel wp
Published Aug 2, 2026
Last Updated Aug 4, 2026
Stay Ahead of the Next One

Get instant alerts for unknown lenxel wp

Be the first to know when new high vulnerabilities affecting unknown lenxel wp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Lenxel WP
0 โ‰ค 1.0.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/84555dc3-b35e-478f-b681-ea0a0fe481d9/

Credits

moonge WPScan