This issue affects Emergency Password Reset: from n/a through 8.0.
Project Subscriptions
No data.
No advisories yet.
Solution
Update the WordPress Emergency Password Reset plugin to the latest available version (at least 9.0).
Workaround
No workaround given by the vendor.
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site request forgery (CSRF) vulnerability in Andy Moyle Emergency Password Reset allows Cross Site Request Forgery. This issue affects Emergency Password Reset: from n/a through 8.0. | |
| Title | WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery (CSRF) vulnerability | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-17T15:30:36.673Z
Reserved: 2024-05-17T10:08:10.961Z
Link: CVE-2024-35648
Updated: 2026-06-17T15:30:28.417Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T14:45:11Z