CVE-2026-14309
Received Received - Intake

Unauthenticated Password Reset in Chat On Desk Order Notifications WordPress Plugin

Vulnerability report for CVE-2026-14309, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
chat_on_desk order_notifications to 1.0.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Chat On Desk Order Notifications WordPress plugin before version 1.0.9. It fails to check if a one-time password was properly validated before allowing a password reset. Attackers can exploit this to reset passwords for any user, including administrators, and gain control of their accounts if SMS-based one-time passwords are enabled.

Detection Guidance

To detect this vulnerability, check if the Chat On Desk Order Notifications WordPress plugin is installed and verify its version. If it is version 1.0.9 or below, it is vulnerable. Inspect the plugin's password reset functionality for improper one-time password validation.

Impact Analysis

If you use this plugin with SMS one-time-password password reset enabled, attackers could reset your password and take over your WordPress account, including admin accounts. This could lead to unauthorized access, data theft, or website defacement.

Compliance Impact

This vulnerability could lead to unauthorized access to user accounts, potentially exposing sensitive personal data. This may violate GDPR's data protection principles and HIPAA's security requirements for safeguarding protected health information.

Mitigation Strategies

Update the Chat On Desk Order Notifications WordPress plugin to version 1.0.9 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14309. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart