CVE-2026-94079: WordPress WP User Manager plugin <= 2.9.19 - Broken Access Control vulnerability
Published Sep 23, 2026
·Updated
Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions.
Affected Software
1 affected component
WP User Manager WP User Manager<=2.9.19
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WP User Manager pluginto a version that resolves this vulnerability.Fixed in 2.9.20
Event History
Sep 23, 2026
CVE Published
via MITRE·06:14 PM
Data Sourced
via MITRE·06:14 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or prior privileges to attempt exploitation.
2
What security impact is indicated?
The provided severity vector indicates network-reachable exploitation with low attack complexity and no user interaction. It indicates an integrity impact, with no stated confidentiality or availability impact.
3
Which plugin versions are affected?
WP User Manager versions 2.9.19 and earlier are identified as affected.