{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/bulk-password-reset--1.3.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:bulk_password_reset_project:bulk_password_reset:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8,"id":"CVE-2026-14873"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Bulk Password Reset (\u003c= 1.3.3)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Bulk Password Reset plugin for WordPress (versions 1.3.3 and below) is susceptible to a privilege escalation vulnerability that allows authenticated attackers with subscriber-level access or higher to compromise administrative accounts. The security flaw stems from the plugin's failure to adequately validate user identities before processing administrative actions. Specifically, an attacker can modify sensitive user details, such as account email addresses, via the plugin's interface. By changing an administrator's email address to one controlled by the attacker, the malicious actor can leverage WordPress's native password reset functionality to regain access to the site as an administrator, ultimately resulting in full site takeover. This vulnerability is significant due to the low barrier to entry, as it only requires an existing subscriber-level account on the target WordPress installation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker registers or gains access to a subscriber-level account on the WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates to the WordPress dashboard using the subscriber account.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the Bulk Password Reset plugin interface.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the plugin's lack of authorization checks to target an administrator account.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the target administrator's profile, specifically changing the associated email address to an attacker-controlled address.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a standard WordPress password reset request for the target administrator account.\u003c/li\u003e\n\u003cli\u003eAttacker receives the password reset link at the attacker-controlled email address.\u003c/li\u003e\n\u003cli\u003eAttacker resets the administrator password and authenticates as the administrator to gain full site control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete site takeover by unauthorized users. Because the attack leverages native WordPress functionality after modifying profile data, the resulting administrative access is often difficult to distinguish from legitimate activity. This poses a critical risk to site integrity, data confidentiality, and overall availability for organizations relying on the affected plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Bulk Password Reset plugin to the latest version immediately, or disable and remove the plugin if a patched version is not yet available.\u003c/li\u003e\n\u003cli\u003eAudit all user accounts for suspicious email address changes, specifically looking for email addresses that do not match the expected corporate or organizational domain.\u003c/li\u003e\n\u003cli\u003eReview audit logs for unusual administrative logins occurring shortly after profile modification events.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for frequent or abnormal POST requests directed at the plugin's configuration or user management endpoints.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-10T05:03:43Z","date_published":"2026-09-10T05:03:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wordpress-bulk-password-reset-vuln/","summary":"The Bulk Password Reset WordPress plugin, versions 1.3.3 and earlier, contains a privilege escalation vulnerability allowing authenticated users to perform unauthorized account takeovers.","title":"Privilege Escalation Vulnerability in Bulk Password Reset WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wordpress-bulk-password-reset-vuln/"}],"language":"en","title":"CraftedSignal Threat Feed - Bulk Password Reset (\u003c= 1.3.3)","version":"https://jsonfeed.org/version/1.1"}