---
id: CVE-2026-14836
title: >-
  The Login & Register Forms  WordPress plugin before 3.2.5 does not properly
  enforce the rate limit on its password-reset verification-code flow, keying
  both the verification code and the per-source attempt counter on an
  unauthenticated, …
summary: >-
  The Login & Register Forms  WordPress plugin before 3.2.5 does not properly
  enforce the rate limit on its password-reset verification-code flow, keying
  both the verification code and the per-source attempt counter on an
  unauthenticated, …
severity: none
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14836'
references:
  - url: 'https://wpscan.com/vulnerability/9bdb7959-dbe7-4f48-892b-b9ee4c8eb060/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00383
epssPercentile: 0.2957
ingestedAt: '2026-08-02T05:17:47.283Z'
---

## Overview

The Login & Register Forms  WordPress plugin before 3.2.5 does not properly enforce the rate limit on its password-reset verification-code flow, keying both the verification code and the per-source attempt counter on an unauthenticated, client-controlled value, allowing unauthenticated attackers to reset the limit at will and brute-force the code to take over any account, including administrators, when the verification-code reset mode is enabled.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
