PatchSiren cyber security CVE debrief
CVE-2025-15018 djanym CVE debrief
CVE-2025-15018 is a critical vulnerability in the Optional Email plugin for WordPress, allowing unauthenticated attackers to escalate privileges via account takeover. The plugin's 'random_password' filter is not restricted to registration contexts, enabling attackers to set a known password reset key and reset the password of any user, including administrators.
- Vendor
- djanym
- Product
- Optional Email
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-07
- Original CVE updated
- 2026-09-30
- Advisory published
- 2026-01-07
- Advisory updated
- 2026-09-30
Who should care
WordPress administrators and security teams should assess exposure and prioritize remediation for installations using the Optional Email plugin version 1.3.11 or earlier. Affected operators must review and update their installations to prevent potential account takeovers. Vulnerability management and security teams should track exceptions, retest remediated assets, and ensure evidence of remediation is documented.
Why it matters
CVE-2025-15018 is a critical vulnerability in the Optional Email plugin for WordPress, allowing unauthenticated attackers to escalate privileges via account takeover. WordPress administrators and security teams should assess exposure and prioritize remediation for installations using the Optional Email plugin version 1.3.11 or earlier.
- Unauthenticated attackers can reset the password of any user, including administrators.
- Attackers can gain access to user accounts, including administrative accounts.
- Privilege escalation can lead to further exploitation of the WordPress installation.
- Remediation priority is high due to the critical CVSS score of 9.8.
Technical summary
The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts. The issue arises from the lack of context-specific restrictions on the 'random_password' filter.
Defensive priority
High priority remediation is recommended for WordPress installations using the Optional Email plugin version 1.3.11 or earlier.
Recommended defensive actions
- Update the Optional Email plugin to a version that restricts the 'random_password' filter to registration contexts.
- Implement additional monitoring to detect potential account takeover attempts.
- Review and update password reset policies for WordPress users.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This issue allows unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts. Evidence is limited to public CVE details and plugin version information up to 1.3.11.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-15018 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-15018
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-15018 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15018
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.