Privilege Escalation Issue in Bulk Password Reset Plugin by WordPress
CVE-2026-14873
8HIGH
What is CVE-2026-14873?
The Bulk Password Reset plugin for WordPress is susceptible to privilege escalation due to inadequate user identity validation. This vulnerability affects all versions prior to 1.3.3. Authenticated users, including those with subscriber-level access, can exploit this weakness to change email addresses of other users, including administrators. This allows an attacker to reset passwords and gain unauthorized access to accounts, compromising the security of the entire site.
Affected Version(s)
Bulk Password Reset 0 <= 1.3.3