CRITICAL
djanym
CVE published 2026-01-07
CVE-2025-15018
CVE-2025-15018 is a critical vulnerability in the Optional Email plugin for WordPress, allowing unauthenticated attackers to escalate privileges via account takeover. The plugin's 'random_password' filter is not restricted to registration contexts, enabling attackers to set a known password reset key and reset the password of any user, including administrators.