CVE-2026-103086: WordPress UsersWP plugin <= 1.2.74 - Broken Access Control vulnerability
Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress UsersWP pluginto a version that resolves this vulnerability.Fixed in 1.2.76
Event History
Frequently Asked Questions
Who can exploit this issue?
The vector indicates network-reachable exploitation with low privileges required and no user interaction. An attacker would need an existing account or other low-privilege access.
What is the impact of successful exploitation?
The provided severity vector indicates high impact to integrity, with no stated impact to confidentiality or availability. The issue is described as missing authorization caused by incorrectly configured access-control security levels.
Which UsersWP versions are affected?
UsersWP versions through 1.2.74 are affected. The available data does not identify a fixed version.