Executive brief
The Bulk Password Reset plugin for WordPress allows authenticated users to change other users' email addresses and reset passwords, including for administrator accounts. An attacker with subscriber-level access can exploit this to take over any account on the site, including gaining full administrative control without requiring administrator approval or verification.
Technical details
The vulnerability is a privilege escalation flaw resulting from insufficient identity validation in the Bulk Password Reset plugin. The plugin fails to verify the user's identity before processing requests to change arbitrary user passwords and email addresses to plugin-configured values. Any authenticated user with subscriber-level access or higher can send requests to reset passwords for other users, including administrators. By changing a target user's email address and then resetting their password, an attacker can gain complete account takeover. The vulnerability affects all versions up to and including 1.3.3.
Affected products
- WordPress Bulk Password Reset up to and including 1.3.3
Timeline
- 2026-09-10: disclosed