{"id":"CVE-2026-14309","title":"The Chat On Desk Order Notifications  WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arb…","summary":"The Chat On Desk Order Notifications  WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arb…","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14309","references":[{"url":"https://wpscan.com/vulnerability/82f14006-c05f-421d-9ba5-bc745e0b2ab8/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00383,"epssPercentile":0.29569,"ingestedAt":"2026-08-02T03:17:05.938Z","slug":"CVE-2026-14309","body":"## Overview\n\nThe Chat On Desk Order Notifications  WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}