---
id: CVE-2026-14873
title: >-
  The Bulk Password Reset plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 1.3.3
summary: >-
  The Bulk Password Reset plugin for WordPress is vulnerable to privilege
  escalation via account takeover in all versions up to, and including, 1.3.3.
  This is due to the plugin not properly validating a user's identity prior to
  updating th…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-862
vendor: rubenw
product: Bulk Password Reset
affected:
  - bulk_password_reset <= 1.3.3
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T21:17:18.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-14873'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/bulk-password-reset/tags/1.3.3/bulk_password_reset.php#L44
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bulk-password-reset/tags/1.3.3/bulk_password_reset.php#L594
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bulk-password-reset/tags/1.3.3/bulk_password_reset.php#L659
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/bulk-password-reset/tags/1.3.3/bulk_password_reset.php#L679
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/93237020-435f-41a6-bcca-fe7b605723ae?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T20:36:55.736562Z'
ingestedAt: '2026-09-12T13:15:15.276Z'
epss: 0.00229
epssPercentile: 0.12215
---

## Overview

The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
