{
  "title": "CVE del giorno — CVE-2026-16300 (CVSS 9,8, critica)",
  "title_variants": [
    {
      "id": "v0",
      "title": "CVE del giorno — CVE-2026-16300 (CVSS 9,8, critica)"
    },
    {
      "id": "v1",
      "title": "CVE-2026-16300: vulnerabilità critica, CVSS 9,8/10, tipo autorizzazione mancante, sfruttabile"
    }
  ],
  "description": "CVE-2026-16300: vulnerabilità critica, CVSS 9,8/10, tipo autorizzazione mancante, sfruttabile da remoto, senza privilegi, senza interazione utente. The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the…",
  "keywords": [
    "cve",
    "cve-2026-16300",
    "vulnerabilità",
    "vulnerabilità critica",
    "cwe-862",
    "cvss",
    "sicurezza informatica",
    "cybersecurity",
    "nvd",
    "aggiornamento di sicurezza"
  ],
  "scenes": [
    {
      "title": "CVE-2026-16300",
      "subtitle": "CVSS 9,8",
      "text": "CVE-2026-16300: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "title": "Autorizzazione mancante",
      "subtitle": "autorizzazione mancante · CVSS v3.1",
      "text": "The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to…"
    },
    {
      "title": "ESPOSIZIONE E MITIGAZIONE",
      "subtitle": "sfruttabile da remoto, senza privilegi, senza interazione utente",
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ],
  "publication_date": "2026-08-05T00:54:44.417Z",
  "duration": 20,
  "topic": "cve",
  "lang": "it",
  "translation_group": "cve-2026-08-05",
  "poster": "cve-2026-08-05.jpg",
  "preview": "cve-2026-08-05.gif",
  "og_card": "cve-2026-08-05.og.jpg",
  "audiogram": "cve-2026-08-05.audiogram.mp4",
  "captions": "cve-2026-08-05.vtt",
  "generation": {
    "procedural": true,
    "ai_generated": [
      "background",
      "voice"
    ],
    "real_data_source": "official public API",
    "filmed_real_event": false,
    "disclosure": "Procedurally generated from real public-source data; abstract AI-generated backgrounds; synthetic (TTS) voice. No real event is filmed or altered."
  },
  "transcript_text": "CVE-2026-16300: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database. The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to… Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD.",
  "transcript": [
    {
      "start": 0,
      "end": 6.667,
      "text": "CVE-2026-16300: gravità critica, punteggio CVSS 9,8 su 10 secondo il National Vulnerability Database."
    },
    {
      "start": 6.667,
      "end": 13.333,
      "text": "The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the password of arbitrary users, including administrators, which could lead to…"
    },
    {
      "start": 13.333,
      "end": 20,
      "text": "Vulnerabilità sfruttabile da remoto, senza privilegi, senza interazione utente. Applica tempestivamente l'aggiornamento del fornitore e consulta l'avviso ufficiale su NVD."
    }
  ]
}