CVE-2026-18035: User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Access Manager pluginto a version that resolves this vulnerability.Fixed in 2.3.15Patch User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18035?
CVE-2026-18035 has a risk rating of 50.
How do I fix CVE-2026-18035?
To fix CVE-2026-18035, update the User Access Manager plugin to version 2.3.15 or later.
What type of access issue does CVE-2026-18035 expose?
CVE-2026-18035 allows unauthenticated users to access restricted content via REST API calls.
Which software is affected by CVE-2026-18035?
CVE-2026-18035 affects the User Access Manager plugin for WordPress.
When was CVE-2026-18035 published?
CVE-2026-18035 was published on August 12, 2026.