Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-15672 | 2 Chamawp, Wordpress | 2 Chamawp, Wordpress | 2026-08-07 | 8.1 High |
| The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is present via other installed code. | ||||
| CVE-2026-16300 | 2 Chamawp, Wordpress | 2 Chamawp, Wordpress | 2026-08-03 | 9.8 Critical |
| The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover. | ||||
Page 1 of 1.