PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-15018 djanym CVE debrief

CVE-2025-15018 is a critical vulnerability in the Optional Email plugin for WordPress, allowing unauthenticated attackers to escalate privileges via account takeover. The plugin's 'random_password' filter is not restricted to registration contexts, enabling attackers to set a known password reset key and reset the password of any user, including administrators.

Vendor
djanym
Product
Optional Email
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

WordPress administrators and security teams should assess exposure and prioritize remediation for installations using the Optional Email plugin version 1.3.11 or earlier. Affected operators must review and update their installations to prevent potential account takeovers. Vulnerability management and security teams should track exceptions, retest remediated assets, and ensure evidence of remediation is documented.

Why it matters

CVE-2025-15018 is a critical vulnerability in the Optional Email plugin for WordPress, allowing unauthenticated attackers to escalate privileges via account takeover. WordPress administrators and security teams should assess exposure and prioritize remediation for installations using the Optional Email plugin version 1.3.11 or earlier.

  • Unauthenticated attackers can reset the password of any user, including administrators.
  • Attackers can gain access to user accounts, including administrative accounts.
  • Privilege escalation can lead to further exploitation of the WordPress installation.
  • Remediation priority is high due to the critical CVSS score of 9.8.

Technical summary

The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.3.11. This is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This makes it possible for unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts. The issue arises from the lack of context-specific restrictions on the 'random_password' filter.

Defensive priority

High priority remediation is recommended for WordPress installations using the Optional Email plugin version 1.3.11 or earlier.

Recommended defensive actions

  • Update the Optional Email plugin to a version that restricts the 'random_password' filter to registration contexts.
  • Implement additional monitoring to detect potential account takeover attempts.
  • Review and update password reset policies for WordPress users.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is due to the plugin not restricting its 'random_password' filter to registration contexts, allowing the filter to affect password reset key generation. This issue allows unauthenticated attackers to set a known password reset key when initiating a password reset, reset the password of any user including administrators, and gain access to their accounts. Evidence is limited to public CVE details and plugin version information up to 1.3.11.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-15018 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-15018

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-15018 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-15018

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.