WordPress security by component
Chat On Desk Order Notifications
Plugin description
Chat On Desk Order Notifications is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.
Plugin slug:
chat-on-desk-order-notificationsLatest vulnerability
CVE-2026-14309: Chat On Desk resets passwords without verifying the SMS code
Chat On Desk Order Notifications before 1.0.9 processes a password-reset request without confirming that the SMS one-time password was successfully validated. When SMS OTP password reset is enabled, an unauthenticated attacker can select an arbitrary user, set a new password and take over the account, including an Administrator account. The published record does not disclose the reset endpoint or action, user and password parameters, OTP-state field or reset function.
| Safe version |
|
||
|---|---|---|---|
| Aug 01, 2026 |
CVE-2026-14309
Chat On Desk resets passwords without verifying the SMS code
Chat On Desk Order Notifications before 1.0.9 processes a password-reset request without confirming that the SMS one-time password was successfully validated. When SMS OTP password reset is enabled, an unauthenticated attacker can select an arbitrary user, set a new password and take over the account, including an Administrator account. The published record does not disclose the reset endpoint or action, user and password parameters, OTP-state field or reset function.
|
1.0.9 |
CVEPending
NVDPending
|