VYPR

WP Password Policy

by WordPress

CVEs (1)

  • CVE-2026-15992HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.00

    The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing authorization checks and nonce verification in the `get_user()` function of the `Module_Password_Hint` class, which unconditionally…