AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-10830

HIGH · CVSS 8.8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

The AllCoach WordPress plugin prior to version 1.0.2 is vulnerable as it fails to verify whether an email address submitted for account registration is already linked to an existing user, enabling unauthenticated attackers to reset passwords for any account, including those of administrators. This flaw poses a significant risk of unauthorized access and potential site takeover. WordPress site administrators and users of the AllCoach plugin should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-10830
Severity
HIGH
CVSS
8.8
EPSS
0.24%
WordPress

Original NVD Description

The AllCoach WordPress plugin before 1.0.2 does not verify that an email address submitted to a public account-registration endpoint is not already associated with an existing user before overwriting that user's password, allowing unauthenticated attackers to reset the password of arbitrary accounts, including administrators, and take over the site.