WordPress 1.5.1.2 and earlier versions have a security flaw which allows attackers to access and modify the contents of an email sent to someone who has forgotten their password. The attackers can do this without needing to be authenticated or identified.