Description
The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Published: 2026-09-10
Score: 8 High
EPSS: n/a
KEV: No
Impact: Account takeover via privilege escalation
Action: Immediate Patch
AI Analysis

Impact

The Bulk Password Reset plugin for WordPress allows an attacker who is authenticated at the subscriber level or higher to change any user's email address to a known custom value set by the plugin. Because the plugin does not properly verify the identity of the user making the change, the attacker can then reset that user's password and gain full access to the account. This flaw represents a privilege escalation that can lead to full site takeover.

Affected Systems

The vulnerability affects all versions of the Bulk Password Reset plugin up to and including 1.3.3. The plugin is maintained by the vendor rubenw and is used on WordPress sites that have installed this add‑on.

Risk and Exploitability

The CVSS score of 8.0 indicates a high‑severity flaw. The EPSS score is not available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, the attack path requires only subscriber‑level access, which is commonly granted. Once the email address is altered, a password reset link can be sent to the custom address, allowing the attacker to assume the victim’s account. The absence of an authorization check is the root cause, classified as CWE‑862.

Generated by OpenCVE AI on September 10, 2026 at 05:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Bulk Password Reset plugin to the latest version that removes the privilege escalation flaw.
  • If an update is not immediately available, temporarily disable or remove the plugin’s password‑reset feature for all users below administrator level.
  • Implement stricter role‑based access controls to prevent subscribers and other non‑admin roles from invoking the bulk‑reset functionality.

Generated by OpenCVE AI on September 10, 2026 at 05:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
Description The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Title Bulk Password Reset <= 1.3.3 - Authenticated (Subscriber+) Arbitrary Password Reset
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-10T03:40:42.058Z

Reserved: 2026-07-06T14:18:17.520Z

Link: CVE-2026-14873

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T04:17:45.480

Modified: 2026-09-10T04:17:45.480

Link: CVE-2026-14873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T05:30:16Z

Weaknesses