CVE-2026-105058: WordPress WP User Profiles plugin <= 2.7.3 - Privilege Escalation vulnerability
Published Oct 6, 2026
·Updated
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
Affected Software
1 affected component
WordPress WP User Profiles<=2.7.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP User Profiles pluginto a version that resolves this vulnerability.Fixed in 2.7.4
Event History
Oct 6, 2026
CVE Published
via MITRE·08:35 AM
Data Sourced
via MITRE·08:35 AM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The vulnerability requires an existing low-privileged account, specifically subscriber-level access. It can be exploited remotely without user interaction.
2
What is the potential impact if exploitation succeeds?
Successful exploitation can result in privilege escalation and has high impacts on confidentiality, integrity, and availability. The affected versions are WP User Profiles 2.7.3 and earlier.