Impact
The Bulk Password Reset plugin for WordPress allows an attacker who is authenticated at the subscriber level or higher to change any user's email address to a known custom value set by the plugin. Because the plugin does not properly verify the identity of the user making the change, the attacker can then reset that user's password and gain full access to the account. This flaw represents a privilege escalation that can lead to full site takeover.
Affected Systems
The vulnerability affects all versions of the Bulk Password Reset plugin up to and including 1.3.3. The plugin is maintained by the vendor rubenw and is used on WordPress sites that have installed this add‑on.
Risk and Exploitability
The CVSS score of 8.0 indicates a high‑severity flaw. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, the attack path requires only subscriber‑level access, which is commonly granted. Once the email address is altered, a password reset link can be sent to the custom address, allowing the attacker to assume the victim’s account. The absence of an authorization check is the root cause, classified as CWE‑862.
OpenCVE Enrichment