← WordPress Vulnerabilities
WordPress security by component

Chat On Desk Order Notifications

Chat On Desk Order Notifications is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: chat-on-desk-order-notifications

CVE-2026-14309: Chat On Desk resets passwords without verifying the SMS code

Chat On Desk Order Notifications before 1.0.9 processes a password-reset request without confirming that the SMS one-time password was successfully validated. When SMS OTP password reset is enabled, an unauthenticated attacker can select an arbitrary user, set a new password and take over the account, including an Administrator account. The published record does not disclose the reset endpoint or action, user and password parameters, OTP-state field or reset function.

PublishedAug 01, 2026
Known safe version1.0.9
Safe version
Aug 01, 2026 CVE-2026-14309
Chat On Desk resets passwords without verifying the SMS code
Chat On Desk Order Notifications before 1.0.9 processes a password-reset request without confirming that the SMS one-time password was successfully validated. When SMS OTP password reset is enabled, an unauthenticated attacker can select an arbitrary user, set a new password and take over the account, including an Administrator account. The published record does not disclose the reset endpoint or action, user and password parameters, OTP-state field or reset function.
1.0.9
CVEPending
NVDPending