Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-15672 2 Chamawp, Wordpress 2 Chamawp, Wordpress 2026-08-07 8.1 High
The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code.
CVE-2026-16300 2 Chamawp, Wordpress 2 Chamawp, Wordpress 2026-08-03 9.8 Critical
The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.