{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/wp-password-policy/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-15992"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Password Policy"],"_cs_severities":["critical"],"_cs_tags":["wordpress","privilege-escalation","web-vulnerability","php"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eA critical privilege escalation vulnerability, tracked as CVE-2026-15992, affects all versions up to and including 3.7.1 of the WP Password Policy plugin for WordPress. This flaw stems from a lack of authorization checks and nonce verification within the \u003ccode\u003eget_user()\u003c/code\u003e function of the \u003ccode\u003eModule_Password_Hint\u003c/code\u003e class. This allows authenticated attackers, possessing at least subscriber-level access, to exploit the vulnerability by submitting a specially crafted HTTP POST request to the password-reset form endpoint. The plugin's vulnerable code unconditionally calls \u003ccode\u003eWP_User::set_role()\u003c/code\u003e with attacker-controlled \u003ccode\u003erole\u003c/code\u003e parameters, enabling an attacker to elevate their own privileges to that of an Administrator. To exploit this, an attacker must have a valid password-reset cookie, which can be easily obtained by initiating a password reset for their own account. This vulnerability poses a significant risk as it grants full administrative control over the compromised WordPress site.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains or possesses authenticated access to a WordPress site at a subscriber level or higher.\u003c/li\u003e\n\u003cli\u003eThe attacker initiates a password reset for their own account on the target WordPress site to obtain a valid password-reset cookie.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious HTTP POST request designed to target the WordPress password-reset form endpoint (typically \u003ccode\u003ewp-login.php\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe crafted POST request includes the \u003ccode\u003eaction\u003c/code\u003e parameter set to \u003ccode\u003ecreateuser\u003c/code\u003e and the \u003ccode\u003erole\u003c/code\u003e parameter set to \u003ccode\u003eadministrator\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003eget_user()\u003c/code\u003e function within the \u003ccode\u003eModule_Password_Hint\u003c/code\u003e class processes these parameters due to missing authorization checks and nonce verification.\u003c/li\u003e\n\u003cli\u003eThe plugin's code unconditionally invokes \u003ccode\u003eWP_User::set_role()\u003c/code\u003e using the attacker-supplied \u003ccode\u003erole\u003c/code\u003e parameter.\u003c/li\u003e\n\u003cli\u003eThe attacker's current subscriber-level account is successfully elevated to an Administrator role, granting full control over the WordPress site.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-15992 allows an authenticated attacker to gain full Administrator privileges on the affected WordPress site. This complete compromise enables the attacker to modify site content, install plugins and themes, delete users, access sensitive data, or inject malicious code, leading to defacement, data theft, or further compromise of the web server. The broad impact extends to any organization or individual using the vulnerable WP Password Policy plugin, regardless of sector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15992 immediately by updating the WP Password Policy plugin to version 3.7.2 or higher.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rule \u0026quot;Detects CVE-2026-15992 Exploitation - WP Password Policy Privilege Escalation\u0026quot; to your SIEM to identify attempts at privilege escalation.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for suspicious POST requests to \u003ccode\u003e/wp-login.php\u003c/code\u003e containing \u003ccode\u003eaction=createuser\u003c/code\u003e and \u003ccode\u003erole=administrator\u003c/code\u003e in the query string or request body.\u003c/li\u003e\n\u003cli\u003eRegularly review user roles and permissions within your WordPress installations for any unauthorized changes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T19:21:45Z","date_published":"2026-07-28T19:21:45Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wp-password-policy-privilege-escalation/","summary":"The WP Password Policy plugin for WordPress, in versions up to and including 3.7.1, is vulnerable to privilege escalation, allowing authenticated attackers with subscriber-level access to escalate their privileges to Administrator by sending a crafted POST request to the password-reset form endpoint, leveraging missing authorization checks and nonce verification.","title":"WP Password Policy Plugin Privilege Escalation via Crafted POST Request (CVE-2026-15992)","url":"https://feed.craftedsignal.io/briefs/2026-07-wp-password-policy-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - WP Password Policy","version":"https://jsonfeed.org/version/1.1"}