Security Advisory

CVE-2025-12866

9.8
CRITICAL

Vulnerability Description

EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote attacker to predict or brute-force the 'forgot password' link, thereby successfully resetting any user's password.
Published Date November 10, 2025
Official Source NIST NVD Advisory