← WordPress Vulnerabilities
WordPress security by component

Login & Register Forms

Login & Register Forms is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Aug 01, 2026; an upstream CVSS base score is still pending.

Plugin slug: login-register-forms

CVE-2026-14836: Login & Register Forms lets visitors reset the password-code rate limit

Login & Register Forms before 3.2.5 keys both its password-reset verification code and per-source attempt counter to an unauthenticated value controlled by the requester. When verification-code reset mode is enabled, an unauthenticated attacker can continually change that value to reset the rate limit, brute-force the code for a selected account and reset its password, including for an Administrator. The record does not disclose the reset endpoint, client-controlled key, code parameter or verification function.

PublishedAug 01, 2026
Known safe version3.2.5
Safe version
Aug 01, 2026 CVE-2026-14836
Login & Register Forms lets visitors reset the password-code rate limit
Login & Register Forms before 3.2.5 keys both its password-reset verification code and per-source attempt counter to an unauthenticated value controlled by the requester. When verification-code reset mode is enabled, an unauthenticated attacker can continually change that value to reset the rate limit, brute-force the code for a selected account and reset its password, including for an Administrator. The record does not disclose the reset endpoint, client-controlled key, code parameter or verification function.
3.2.5
CVEPending
NVDPending