๐Ÿ” CVE Alert

CVE-2026-12586

UNKNOWN 0.0

Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.

Vendor unknown
Product lenxel wp
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown lenxel wp

Be the first to know when new unknown vulnerabilities affecting unknown lenxel wp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Lenxel WP
0 โ‰ค 1.0.31

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/84555dc3-b35e-478f-b681-ea0a0fe481d9/

Credits

moonge WPScan