CVE-2026-12586: Lenxel WP <= 1.0.31 - Unauthenticated Account Takeover via Arbitrary Password Reset
The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12586?
CVE-2026-12586 has a risk rating of 89, indicating a high severity level.
What systems are affected by CVE-2026-12586?
CVE-2026-12586 affects Lenxel WP WordPress theme versions up to and including 1.0.31.
How do I fix CVE-2026-12586?
To fix CVE-2026-12586, you should update the Lenxel WP theme to the latest version that addresses this vulnerability.
What kind of attack does CVE-2026-12586 enable?
CVE-2026-12586 allows unauthenticated attackers to reset passwords and take over user accounts, including administrative accounts.
What is the nature of the vulnerability in CVE-2026-12586?
CVE-2026-12586 is a CSRF vulnerability that does not verify authorization or ownership during password reset actions.