CVE-2026-15992

Source
https://cve.org/CVERecord?id=CVE-2026-15992
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-15992.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-15992
Published
2026-07-28T18:35:51Z
Modified
2026-10-06T02:35:51Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation
Details

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the get_user() function of the Module_Password_Hint class, which unconditionally calls WP_User::set_role() with the attacker-supplied role parameter on any account resolved via $_POST['user_login'], without confirming the requesting user holds the capability to assign roles. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their own privileges to Administrator by submitting a crafted POST request — with action set to createuser and role set to administrator — to the password-reset form endpoint. The vulnerable code path is reachable via the password_hint filter hooked during the WordPress password-reset form render, meaning an attacker need only possess a valid password-reset cookie to reach the sink.

Database specific
{
    "cna_assigner":  "Wordfence",
    "cwe_ids":  [
        "CWE-269"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15992.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "last_affected":  "3.7.1"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

WordPress:Plugin / password-requirements

Package

Name
password-requirements

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.7.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-15992.json"