pravel_change_password of the file admin-ajax.php of the component AJAX Handler. This manipulation of the argument reset_activation_code causes weak password recovery.
The identification of this vulnerability is CVE-2026-12417. It is possible to initiate the attack remotely. There is no exploit available.
Intelligence View
SOCIAL SHARE CARD GENERATOR