CVE-2026-16300: Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset
Published Aug 3, 2026
·Updated
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.
Affected Software
1 affected component
ChamaWP WordPress plugin<1.0.13
Event History
Aug 3, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness