CVE-2025-22736: WordPress User Management plugin <= 1.2 - Privilege Escalation vulnerability
Published Jan 15, 2025
·Updated
Incorrect Privilege Assignment vulnerability in Saad Iqbal User Management user-management allows Privilege Escalation.This issue affects User Management: from n/a through <= 1.2.
Affected Software
1 affected component
Saad Iqbal WordPress User Management plugin<=1.2
Event History
Jan 15, 2025
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-22736?
CVE-2025-22736 is a critical vulnerability that allows privilege escalation in WPExperts User Management.
2
How do I fix CVE-2025-22736?
To fix CVE-2025-22736, update the WPExperts User Management plugin to the latest version beyond 1.2.
3
What versions are affected by CVE-2025-22736?
CVE-2025-22736 affects versions of WPExperts User Management up to and including 1.2.
4
Is CVE-2025-22736 specific to WordPress?
Yes, CVE-2025-22736 specifically affects the WPExperts User Management plugin used within WordPress.
5
What are the risks of not addressing CVE-2025-22736?
Failing to address CVE-2025-22736 can lead to unauthorized users gaining elevated privileges, compromising site security.