This is a heavily interactive web application, and JavaScript is required. Simple HTML interfaces are possible, but that is not what this is.
Post
Pulse WP
pulse-wp.com
did:plc:m7puovzqhxurz66hip2xwfs6
Anyone can reset any user password. Admin accounts included. CVE-2026-11387 (CVSS 9.8). SMS Alert plugin through 3.9.5 doesn't validate identity before password resets. Your site is takeover-ready.
Update to 3.9.5 now. Scan your WordPress site: pulse-wp.com
#WordPress #AccessControl #CyberSecurity
2026-07-02T00:00:12.824Z