WordPress security by component
ChamaWP
Plugin description
ChamaWP is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 03, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
chamawpLatest vulnerability
CVE-2026-16300: ChamaWP lets visitors reset any WordPress account password
ChamaWP before 1.0.13 does not correctly validate password-reset requests. An unauthenticated attacker can select an arbitrary WordPress user, reset that account's password and take it over, including an Administrator account. The CNA record does not disclose the reset route, account identifier, verification token, password fields or callback.
| Safe version |
|
||
|---|---|---|---|
| Aug 03, 2026 |
CVE-2026-16300
ChamaWP lets visitors reset any WordPress account password
ChamaWP before 1.0.13 does not correctly validate password-reset requests. An unauthenticated attacker can select an arbitrary WordPress user, reset that account's password and take it over, including an Administrator account. The CNA record does not disclose the reset route, account identifier, verification token, password fields or callback.
|
1.0.13 |
CVE9.8
NVDPending
|
| Aug 03, 2026 |
CVE-2025-15672
ChamaWP exposes unauthenticated PHP object injection
ChamaWP before 1.0.13 passes unauthenticated attacker-controlled input to a PHP deserialization function without adequate validation. An attacker can inject arbitrary PHP objects; if another installed component supplies a compatible gadget chain, object wakeup or destruction behavior may lead to remote code execution. The CNA record does not disclose the endpoint, parameter, serialized format, deserialization function or a confirmed gadget chain.
|
1.0.13 |
CVE8.1
NVDPending
|