CVE-2026-12586
Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.
| Vendor | unknown |
| Product | lenxel wp |
| Published | Aug 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown lenxel wp
Be the first to know when new unknown vulnerabilities affecting unknown lenxel wp are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Lenxel WP
0 โค 1.0.31
References
Credits
moonge WPScan