Description
The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
Published: 2026-08-01
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Chat On Desk Order Notifications WordPress plugin prior to version 1.0.9. It fails to confirm the one‑time password (OTP) before carrying out a password‑reset request, allowing attackers who are not logged in to overwrite a user’s password. If the plugin’s SMS OTP reset feature is active, the attacker can reset any user’s password, including that of an administrator, and thereby seize control of the account. This results in full compromise of the affected site’s administrative interface and any sensitive data the user can access.

Affected Systems

The affected product is the Chat On Desk Order Notifications plugin for WordPress. All installations using a version earlier than 1.0.9 are vulnerable, regardless of the host server or WordPress theme employed. No specific vendor name is listed, but the plugin is distributed as a community WordPress add‑on and may be installed on both shared and dedicated hosting environments.

Risk and Exploitability

The EPSS score is under 1 %, indicating a low probability of public exploitation at this time, and the vulnerability is not yet included in the CISA KEV catalog. The CVSS score of 8.1 places this flaw in the high severity range. Nevertheless, the potential impact is severe because unauthenticated attackers can take over any user account. The attack path requires an attacker to trigger a password reset via the plugin’s public interface, bypass the OTP check, and submit a new password. As no authentication is required to drive the chain, automated scripts could be used to compromise multiple sites.

Generated by OpenCVE AI on August 5, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Chat On Desk Order Notifications plugin to version 1.0.9 or newer, which validates the OTP before resetting the password.
  • Temporarily disable the SMS OTP password‑reset feature until a patched version is installed.
  • Remove or deactivate the Chat On Desk Order Notifications plugin if it is no longer needed.
  • Verify that no other plugins or custom code bypass OTP or perform password resets without proper verification.

Generated by OpenCVE AI on August 5, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Wed, 05 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 02 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Sat, 01 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Chat On Desk Order Notifications WordPress plugin before 1.0.9 does not verify that the one-time password has been validated before processing a password-reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, and take over their accounts when SMS one-time-password password reset is enabled.
Title Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T16:19:58.260Z

Reserved: 2026-07-01T11:24:36.156Z

Link: CVE-2026-14309

cve-icon Vulnrichment

Updated: 2026-08-05T16:15:40.579Z

cve-icon NVD

Status : Received

Published: 2026-08-01T07:16:30.207

Modified: 2026-08-05T17:16:40.963

Link: CVE-2026-14309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T20:30:06Z

Weaknesses