CVE-2026-14919

cvss 9.8

Attackers can trick your WordPress site into sending password reset links to their own email, letting them steal admin accounts.

Patch now

why it matters — synthesized by an LLM from the sources below

signal timeline

first seen 1h ago · last seen 9m ago

intelyard daily

One short email each weekday: what mattered in tech, written from source data and checked by a human. No account needed, one-click unsubscribe, and we never sell or share the address.