CVE-2026-12981
Received Received - Intake

CAFEHAUS API WordPress Plugin Password Reset Vulnerability

Vulnerability report for CVE-2026-12981, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-24

Last updated on: 2026-07-24

Assigner: WPScan

Description

The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthenticated attackers to set the password of any user, including administrators, and fully take over their accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-24
Last Modified
2026-07-24
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cafehaus api_plugin to 1.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The CAFEHAUS API WordPress plugin through version 1.0.0 has a vulnerability that allows unauthenticated attackers to reset passwords for any user, including administrators, without needing authentication or authorization. This flaw enables complete account takeover of affected users.

Detection Guidance

Check if the CAFEHAUS API WordPress plugin version 1.0.0 or below is installed. Look for unauthorized password reset requests or changes in user accounts. Monitor logs for suspicious activity related to user password modifications.

Impact Analysis

An attacker could exploit this to gain full control over any user account on a vulnerable WordPress site, including admin accounts. This could lead to unauthorized access, data theft, website defacement, or further compromise of the site and its users.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face legal penalties, loss of trust, and reputational damage if user data is compromised due to this flaw.

Mitigation Strategies

Immediately disable the CAFEHAUS API plugin if installed. Remove the plugin files from the server. Reset passwords for all users, especially administrators, and enforce strong password policies. Monitor accounts for unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-12981. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart