← WordPress Vulnerabilities
WordPress security by component

ChamaWP

ChamaWP is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.8.

Plugin slug: chamawp

CVE-2026-16300: ChamaWP lets visitors reset any WordPress account password

ChamaWP before 1.0.13 does not correctly validate password-reset requests. An unauthenticated attacker can select an arbitrary WordPress user, reset that account's password and take it over, including an Administrator account. The CNA record does not disclose the reset route, account identifier, verification token, password fields or callback.

PublishedAug 03, 2026
Known safe version1.0.13
Published vulnerabilities for chamawp
Safe version
Aug 03, 2026 CVE-2026-16300
ChamaWP lets visitors reset any WordPress account password
ChamaWP before 1.0.13 does not correctly validate password-reset requests. An unauthenticated attacker can select an arbitrary WordPress user, reset that account's password and take it over, including an Administrator account. The CNA record does not disclose the reset route, account identifier, verification token, password fields or callback.
1.0.13
CVE9.8
NVDPending
Aug 03, 2026 CVE-2025-15672
ChamaWP exposes unauthenticated PHP object injection
ChamaWP before 1.0.13 passes unauthenticated attacker-controlled input to a PHP deserialization function without adequate validation. An attacker can inject arbitrary PHP objects; if another installed component supplies a compatible gadget chain, object wakeup or destruction behavior may lead to remote code execution. The CNA record does not disclose the endpoint, parameter, serialized format, deserialization function or a confirmed gadget chain.
1.0.13
CVE8.1
NVDPending