CVE-2025-15018 | Optional Email Plugin up to 1.3.11 on WordPress Password Reset random_password password recovery
A vulnerability labeled as critical has been found in Optional Email Plugin up to 1.3.11 on WordPress. This impacts the function random_password of the component Password Reset Handler. Executing a manipulation can lead to weak password recovery.
This vulnerability is tracked as CVE-2025-15018. The attack can be launched remotely. No exploit exists.