---
id: CVE-2025-15018
title: >-
  The Optional Email plugin for WordPress is vulnerable to Privilege Escalation
  via Account Takeover in all versions up to, and including, 1.3.11
summary: >-
  The Optional Email plugin for WordPress is vulnerable to Privilege Escalation
  via Account Takeover in all versions up to, and including, 1.3.11. This is due
  to the plugin not restricting its 'random_password' filter to registration
  conte…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-639
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15018'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/optional-email/tags/1.3.11/optional-email.php?marks=44,51#L44
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/ff4243e9-cf72-40d5-bc7d-204426024a1d?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00341
epssPercentile: 0.25159
ingestedAt: '2026-09-30T22:27:27.717Z'
---

## Overview

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
