Junglewise Threat Intelligence

CVE-2026-14309: Chat On Desk Order Notifications authentication bypass in password reset

CVE-2026-14309 · Severity: info · CVSS 8.1 · Published 2026-08-01

Executive brief

A vulnerability in the Chat On Desk Order Notifications plugin for WordPress allows unauthorized individuals to take over any user account, including administrator accounts. This occurs because the plugin fails to properly verify security codes during the password reset process when SMS notifications are enabled. An attacker could use this flaw to gain full control of a website, potentially leading to data theft, site defacement, or complete service disruption.

Technical details

The Chat On Desk Order Notifications plugin for WordPress (versions prior to 1.0.9) contains an authentication bypass vulnerability in its password reset logic. The root cause is a failure to verify that a one-time password (OTP) has been successfully validated before proceeding to update the user's password. When the SMS OTP password reset feature is enabled, an unauthenticated remote attacker can bypass the verification step and reset the password for any user, including administrators, by sending a crafted request. This leads to full account takeover. The issue is fixed in version 1.0.9.

Affected products

  • Unknown Chat On Desk Order Notifications < 1.0.9

Timeline

  • 2026-07-17: disclosed: Publicly published on WPScan
  • 2026-07-31: patched: Last updated/confirmed fix version 1.0.9
  • 2026-08-01: advisory: NVD publication date

References