CVE-2026-18469
The WordPress plugin "Login & Register Forms" before version 4.0.2 fails to properly enforce a password reset attempt limit, allowing an attacker to reset the limit and brute-force a verification code to gain unauthorized access to any account, including administrator accounts. This vulnerability is particularly concerning because it can be exploited by unauthenticated attackers, making it easier for them to gain control of a website. The issue arises from the plugin's reliance on client-controlled data to verify the verification code and track attempt counts.
Based on public CVE data (MITRE/NVD).