CVE-2026-18960: Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords
Published Aug 10, 2026
·Updated
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Affected Software
1 affected component
WordPress plugin Block User Account<2.0.1
Event History
Aug 10, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18960?
CVE-2026-18960 has a risk severity score of 65.
2
How do I fix CVE-2026-18960?
To fix CVE-2026-18960, update the Block User Account plugin to version 2.0.1 or later.
3
What does CVE-2026-18960 allow?
CVE-2026-18960 allows blocked users to retain access through application passwords created before the account was blocked.
4
Which software is affected by CVE-2026-18960?
CVE-2026-18960 affects the Block User Account plugin for WordPress.
5
When was CVE-2026-18960 published?
CVE-2026-18960 was published on August 10, 2026.