VYPR

ChamaWP

by WordPress

CVEs (2)

  • CVE-2026-16300CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.00

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to a full site takeover.

  • CVE-2025-15672HigAug 3, 2026
    risk 0.53cvss 8.1epss 0.00

    The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unauthenticated attackers to inject arbitrary PHP objects, which could lead to remote code execution when a suitable gadget chain is…