#Password Reset
All CosmicBytez Labs articles tagged #Password Reset, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-14364: TrueBooker WordPress Plugin Account Takeover via Password Reset Bypass
A critical unauthenticated account takeover vulnerability in the TrueBooker Appointment Booking plugin for WordPress allows attackers to reset any user's...
- Security
CVE-2026-9701: WordPress Eventer Plugin — Insecure Password Reset Enables Account Takeover
A critical CVSS 9.8 vulnerability in the Eventer WordPress plugin exposes plaintext password reset keys in user meta, allowing unauthenticated attackers...
- Security
CVE-2026-13498: SQL Injection in Restaurant Management System via Password Reset
A high-severity SQL injection vulnerability in yashpokharna2555's restaurant management system allows unauthenticated attackers to exploit the...
- Security
CVE-2026-8206: Kirki WordPress Plugin Critical Privilege Escalation via Account Takeover
The Kirki Freeform Page Builder plugin for WordPress (versions 6.0.0–6.0.6) allows unauthenticated attackers to take over any user account during password…
- Security
CVE-2026-35676: phpMyFAQ Unauthenticated Password Reset Vulnerability
phpMyFAQ before 4.1.3 contains a CVSS 8.2 flaw allowing unauthenticated attackers to reset any account password without token validation, enabling full...
- Security
CVE-2026-24467: OpenAEV Password Reset Account Takeover
OpenAEV's password reset implementation contains multiple chained weaknesses enabling reliable account takeover in versions 1.0.0 through 2.0.12 of the...