Privilege Escalation Issue in Bulk Password Reset Plugin by WordPress
CVE-2026-14873

8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 September 2026

What is CVE-2026-14873?

The Bulk Password Reset plugin for WordPress is susceptible to privilege escalation due to inadequate user identity validation. This vulnerability affects all versions prior to 1.3.3. Authenticated users, including those with subscriber-level access, can exploit this weakness to change email addresses of other users, including administrators. This allows an attacker to reset passwords and gain unauthorized access to accounts, compromising the security of the entire site.

Affected Version(s)

Bulk Password Reset 0 <= 1.3.3

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Afan
moonge
.