CVE-2026-15992
teydeastudio WP Password Policy
The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally calls `WP_User::set_role()` with the attacker-supplied `role` parameter on any account resolved via `$_POST['user_login']`, without confirming the requesting user holds the capability to assign roles. This makes it possible for authenticated attackers, with subscriber-level access and above, to escalate their own pr...
- CVSS
- 8.8
- EPSS
- 0.27% 19.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29