One given example is that – in the case of the Return-Path header being maliciously set – the attacker could perform a DoS attack on the victim's mailbox so that the password reset email would be sent as part of a non-delivery receipt.
Also, if the victim has an auto-responder enabled, the attacker will receive an out of office reply, with the password reset link quoted in the email.
I've never seen an autoreply that's included the original message
It was always rare, but it used to be more common than it is now.
Another way to trigger a bounce would be to have the evil domain purposefully having strict SPF and DMARC policy set.
this depends on recipient's (WP admin) server properly validating SPF and DMARC
It has to be combined with another attack. If the victim's mail server bounces the email it will be sent back to the attacker's mail server. One possible approach to do that is to fill the target email so they reach their quota.