Today we’re publishing important security updates for both the free and PRO editions of WP Password Policy. This release patches a privilege escalation vulnerability on the password reset form and restores compatibility with PHP 7.4. We recommend updating as soon as possible.
Shared Updates (Free 3.7.2 & PRO 3.14.2)
- Password reset privilege escalation fixed: A crafted request to the password reset form could assign any role, including Administrator, to an existing account. Exploiting it required a valid password reset link for an account the attacker already controls, but the potential impact warranted an immediate patch. Accounts are now protected regardless of how the reset form is submitted.
- PHP 7.4 compatibility restored: A recent change introduced PHP 8.0+ syntax into the password compliance check, which caused an error on sites still running PHP 7.4. That syntax has been corrected, and the plugin runs cleanly on PHP 7.4 again.
You can download the latest versions of the WP Password Policy plugin directly from WordPress.org (Free version) or the Customer Portal (PRO version).
For questions and help about this release, please get in touch with our support team.