CVE-2026-88827: Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords
Published Oct 11, 2026
·Updated
The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
Affected Software
1 affected component
WordPress Disable Users<=1.0.5
Event History
Oct 11, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·07:17 AM
Description