---
id: CVE-2026-12586
title: >-
  The Lenxel WP WordPress theme through 1.0.31 does not perform any
  authorization or ownership check on its password-reset action, validating only
  a CSRF nonce, allowing unauthenticated attackers to reset the password of any
  user (includin…
summary: >-
  The Lenxel WP WordPress theme through 1.0.31 does not perform any
  authorization or ownership check on its password-reset action, validating only
  a CSRF nonce, allowing unauthenticated attackers to reset the password of any
  user (includin…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12586'
references:
  - url: 'https://wpscan.com/vulnerability/84555dc3-b35e-478f-b681-ea0a0fe481d9/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T09:18:12.196Z'
epss: 0.002
epssPercentile: 0.08803
---

## Overview

The Lenxel WP WordPress theme through 1.0.31 does not perform any authorization or ownership check on its password-reset action, validating only a CSRF nonce, allowing unauthenticated attackers to reset the password of any user (including an administrator) and take over the account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
