CVE-2026-12417 | pravel SignUp & SignIn Plugin up to 1.0.0 on WordPress AJAX admin-ajax.php pravel_change_password reset_activation_code password recovery

SecurityVulns

A vulnerability, which was classified as critical, has been found in pravel SignUp & SignIn Plugin up to 1.0.0 on WordPress. This impacts the function pravel_change_password of the file admin-ajax.php of the component AJAX Handler. This manipulation of the argument reset_activation_code causes weak password recovery.

The identification of this vulnerability is CVE-2026-12417. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More