5
I agree with Bender here - the user must know that the password retrieval procedure is completely without intervention from a webmaster. Even though the password is changed to the one sent in the email, I wouldn't like it, if that was the case.
You can, however, send an additional PM/email to the webmaster(s) that this user has requested a new password, so you can monitor if the feature is being abused. But I would advice against your idea.