216.73.216.233

CVE-2025-15018

· Published 07/01/2026 12:16 · Modified 08/01/2026 18:08

Labels: CVE-2025-15018 2026-01-07CVE-2025-15018CWE-639[email protected]

Essential information

Published
07/01/2026 12:16
Modified
08/01/2026 18:08
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / optional email plugin cpe:2.3:a:wordpress:optional_email_plugin:*:*:*:*:*:wordpress:*:*

References