Junglewise Threat Intelligence

CVE-2026-15992: WP Password Policy privilege escalation in Module_Password_Hint

CVE-2026-15992 · Severity: high · CVSS 8.8 · Published 2026-07-28

Executive brief

The WP Password Policy plugin for WordPress, which is used to manage and enforce password security requirements, contains a flaw that allows low-level users to upgrade their own account permissions. By exploiting this vulnerability, an attacker with a standard user account can grant themselves full administrative control over the website. This could lead to a complete site takeover, unauthorized access to sensitive customer data, and the ability to modify or delete site content.

Technical details

The vulnerability is classified as Improper Privilege Management (CWE-269) within the `Module_Password_Hint` class. The `get_user()` function fails to perform authorization checks or nonce verification before calling `WP_User::set_role()` with an attacker-supplied `role` parameter. An authenticated attacker with subscriber-level access can trigger this by submitting a crafted POST request to the password-reset form endpoint while possessing a valid password-reset cookie. By setting the `action` to `createuser` and `role` to `administrator`, the attacker can escalate their privileges to the highest level. The issue affects all versions up to and including 3.7.1.

Affected products

  • teydeastudio WP Password Policy up to and including 3.7.1

Timeline

  • 2026-07-28: disclosed: Vulnerability published by Wordfence and NVD

References