diff --git a/src/wp-login.php b/src/wp-login.php
index 96eef5b27d..1c2428217f 100644
--- a/src/wp-login.php
+++ b/src/wp-login.php
@@ -294,7 +294,7 @@ function retrieve_password() {
if ( empty( $_POST['user_login'] ) ) {
$errors->add('empty_username', __('ERROR: Enter a username or email address.'));
} elseif ( strpos( $_POST['user_login'], '@' ) ) {
- $user_data = get_user_by( 'email', trim( $_POST['user_login'] ) );
+ $user_data = get_user_by( 'email', trim( wp_unslash( $_POST['user_login'] ) ) );
if ( empty( $user_data ) )
$errors->add('invalid_email', __('ERROR: There is no user registered with that email address.'));
} else {