Impact
The CAFEHAUS API WordPress plugin up to version 1.0.0 lacks authentication or authorization checks when updating user passwords, allowing any visitor to set the password for any user, including administrators, leading to full account compromise as described in the CVE. This is a credential management flaw identified as CWE‑269.
Affected Systems
WordPress installations that have the CAFEHAUS API plugin installed with a version equal to or earlier than 1.0.0 are affected. The vendor/product is listed in the CNA data as Unknown:CAFEHAUS API.
Risk and Exploitability
With a CVSS score of 7.5 the vulnerability is rated high severity. Its EPSS score of less than 1 percent indicates a low current likelihood of exploitation, and it is not present in CISA’s KEV catalog. The likely attack vector is a direct HTTP request to the plugin’s password reset endpoint, which does not require any authentication or authorization, allowing an unauthenticated attacker to trigger the reset and take over any account.
OpenCVE Enrichment