CVE-2026-14836
Received Received - Intake

Password Reset Brute Force in Login & Register Forms WordPress Plugin

Vulnerability report for CVE-2026-14836, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-01

Last updated on: 2026-08-01

Assigner: WPScan

Description

The Login & Register Forms WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-01
Last Modified
2026-08-01
Generated
2026-08-01
AI Q&A
2026-08-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpforms login_and_register_forms to 3.2.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Login & Register Forms WordPress plugin before version 3.2.5. It fails to properly enforce rate limits on password-reset verification codes by using a client-controlled value to track attempts. This allows attackers to bypass rate limits and brute-force the verification codes, potentially taking over any account including administrators if the verification-code reset mode is enabled.

Detection Guidance

To detect this vulnerability, check if the Login & Register Forms WordPress plugin is running a version before 3.2.5. Inspect the plugin's password-reset flow for improper rate limiting enforcement. Look for repeated password reset attempts from the same source without blocking. No specific commands are provided in the context.

Impact Analysis

If you use this WordPress plugin with version before 3.2.5, an attacker could exploit this to reset passwords and gain unauthorized access to any account on your site, including admin accounts. This could lead to data theft, site defacement, or further compromise of your WordPress installation.

Compliance Impact

This vulnerability allows unauthenticated attackers to brute-force password reset codes, potentially gaining unauthorized access to user accounts. This could lead to unauthorized data access or modification, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information.

Mitigation Strategies

Update the Login & Register Forms WordPress plugin to version 3.2.5 or later to address the improper rate limit enforcement issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14836. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart