CVE-2026-28163: WordPress New User Approve plugin <= 3.2.8 - Broken Access Control vulnerability
Published Aug 20, 2026
·Updated
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects New User Approve: from n/a through 3.2.8.
Affected Software
1 affected component
WordPress plugin myCred New User Approve<=3.2.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress New User Approve pluginto a version that resolves this vulnerability.Fixed in 3.2.9
Event History
Aug 20, 2026
CVE Published
via MITRE·12:36 PM
Data Sourced
via MITRE·12:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What does the attack vector indicate about exploitation requirements?
The CVSS vector indicates the issue is network-accessible, has low attack complexity, requires no privileges, and requires no user interaction. Successful exploitation can affect integrity, while confidentiality and availability are not indicated as affected.
2
Which versions should be considered affected?
The affected range is listed as New User Approve versions through 3.2.8. No fixed version is provided in the available data.