CVE-2026-103085: WordPress WP User Manager plugin <= 2.9.20 - Privilege Escalation vulnerability
Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wp-user-managerto a version that resolves this vulnerability.Fixed in 2.9.21
Event History
Frequently Asked Questions
Who can exploit this issue?
The CVSS vector indicates it can be exploited remotely without prior privileges or user interaction. The provided data does not identify any additional prerequisites.
What versions are affected?
WP User Manager versions through 2.9.20 are affected. The lower bound is unspecified in the available data.
What is the likely security impact?
The issue is described as privilege abuse through improper access control. The assigned vector indicates low confidentiality and integrity impact, with no availability impact.