Hello
As far as I remember does the forgot password function send an email to you and then you can change the password using an in the email mentioned one time link. So, even if someone else starts this process for you it's not that much of a use for him since just you will get this email with that link...
I understand correctly that your password was not changed by someone else, right?
Much more interesting is the possibility to send planeshift people emails with a cross site scripting in it (assuming there is one on the webpage). This way they might be able to fake the password change process. In case you enter your valid password again they'd know it, for example.
Even better would be a SQL-Injection where you can alter or get some information on the account/game database

Unfortunately do I not know of either vulnerability though the forum mentions some sql error for the applying-function......

But, in general, if I remember the process right there's not much you can do since, as said, even entering valid email-addresses doesn't help an attacker much since he doesn't get the password-change-link.
Sen