CVE-2026-14873
Deferred Deferred - Pending Action

Privilege Escalation via Account Takeover in Bulk Password Reset WordPress Plugin

Vulnerability report for CVE-2026-14873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Wordfence

Description

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
bulk_password_reset bulk_password_reset to 1.3.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Bulk Password Reset WordPress plugin up to version 1.3.3 allows authenticated attackers with subscriber-level access or higher to escalate privileges by changing any user's email address, including administrators, and resetting their password. This leads to full account takeover of the WordPress site.

Detection Guidance

Check WordPress sites for the Bulk Password Reset plugin versions up to 1.3.3. Look for unauthorized password changes or email modifications in user accounts. Review plugin settings for suspicious custom password configurations.

Impact Analysis

An attacker could gain control of administrator accounts, allowing them to install malicious plugins, modify site content, steal data, or completely take over your WordPress site. Even lower-privilege users could escalate to admin access.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Compliance failures may result in legal penalties and reputational damage.

Mitigation Strategies
  • Update the Bulk Password Reset plugin to the latest version immediately to patch the vulnerability.
  • Review all user accounts, especially administrators, for unauthorized changes to email addresses or passwords.
  • Revoke access for any suspicious or unknown accounts that may have been created due to this vulnerability.
  • Monitor for unusual activity, such as multiple password reset requests or unauthorized privilege changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14873. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart