Home Ripetizioni Consulenza Cybersecurity 📖 Libro Contattami
HomeCybersecurity › CVE-2026-14873
CVSS 8.0 — ALTO

CVE-2026-14873 — Vulnerabilità HIGH su N/A

Pubblicato il 2026-09-10 · Fonte: NVD NIST

CVE ID
CVE-2026-14873
CVSS Score
8.0
Vendor
N/A
Prodotti
N/A
Exploit pubblico
Non noto
Sfruttata (CISA)
No
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Riassunto tecnico

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to cha

Impatto

Vulnerabilità con punteggio CVSS 8.0 (HIGH). Sfruttata attivamente: No.

Sistemi vulnerabili

Vendor: N/A
Prodotti: N/A

Mitigazioni

Applicare le patch del vendor appena disponibili. Monitorare gli advisory ufficiali.

Vuoi approfondire la cybersecurity? Scopri il libro "Ethical Hacker per Tutti" oppure prenota una lezione online.