{"id":"CVE-2026-14836","title":"The Login & Register Forms  WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, …","summary":"The Login & Register Forms  WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, …","severity":"none","published":"2026-08-01","updated":"2026-08-01","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14836","references":[{"url":"https://wpscan.com/vulnerability/9bdb7959-dbe7-4f48-892b-b9ee4c8eb060/","label":"contact@wpscan.com"}],"tags":["nvd"],"epss":0.00226,"epssPercentile":0.13601,"ingestedAt":"2026-08-02T05:17:47.283Z","slug":"CVE-2026-14836","body":"## Overview\n\nThe Login & Register Forms  WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}