Sceawere

Vulnerability Detail

CVE-2026-103085UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WP User Manager Privilege Abuse

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
2h ago
Vendor
WP User Manager
Product
WP User Manager
Attack Type
Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T19:17:13.240Z",
  "pubdate": "2026-10-05T19:17:13.240Z",
  "executiveSummary": "The WP User Manager plugin for WordPress is affected by an Improper Access Control vulnerability that enables Privilege Abuse. This flaw allows unauthorized or low-privileged users to perform actions exceeding their intended authorization levels, potentially leading to a complete compromise of administrative functionality within the WordPress environment.\nThe vulnerability resides in versions from n/a through 2.9.20 of the WP User Manager plugin. The core issue involves the failure to adequately enforce access control checks on sensitive endpoints or administrative functions, permitting attackers to bypass restrictive security boundaries.\nRisk implications include the potential for unauthorized privilege escalation, account takeover, or unauthorized configuration changes. The exploitation of this vulnerability requires no specialized hardware but may depend on the attacker's ability to interact with the plugin's insecurely exposed interface or functions. Given that the plugin is designed to manage user roles and capabilities, the impact of such an authorization bypass is critical, as it undermines the fundamental security model of the affected WordPress site.",
  "technicalDetails": "The vulnerability is classified as an Improper Access Control issue, stemming from the insufficient validation of user capabilities during the execution of critical administrative logic within the WP User Manager plugin. In the context of WordPress plugins, access control is typically enforced through the 'current_user_can()' function or similar permission-based checks that verify whether the requesting user possesses the necessary 'capability' to execute a specific task.\nRoot cause analysis indicates that the affected version range (n/a through 2.9.20) failed to implement rigorous authorization checks on specific REST API endpoints or AJAX handlers utilized by the plugin for user management tasks. When these endpoints are invoked, the underlying codebase processes the request without confirming if the authenticated user has the appropriate administrative privileges to modify user profiles, adjust security settings, or perform high-level account operations.\nThe attack flow involves an authenticated user—who may hold a low-privilege role such as 'Subscriber'—crafting a specially formed HTTP request targeting the vulnerable component. By submitting malicious parameters to the insecurely exposed functions, the attacker can force the plugin to execute unauthorized operations. Since the component responsible for these actions lacks a secondary verification layer, it incorrectly assumes that the request originated from a legitimate administrative source, thereby processing the request as if it were authorized.\nExploitation allows for Privilege Abuse, where the attacker may alter their own user role, modify other users' attributes, or trigger administrative actions that the application context should have restricted. Because the plugin interfaces with the WordPress user database, the post-exploitation impact is severe, potentially resulting in unauthorized administrative access, the creation of backdoors via administrative account modification, or the illicit extraction of sensitive user data.\nThis vulnerability is exposed via the web interface and is accessible over the network. It does not require complex reconnaissance beyond identifying the existence of the vulnerable plugin version and mapping the corresponding insecure endpoints. The lack of granular capability checks means the plugin trusts client-side input in critical logic paths, which effectively elevates the privileges of any attacker who successfully interacts with the vulnerable functionality. The vulnerability remains present across all configurations using the specified plugin versions until the access control logic is correctly implemented using WordPress core permission verification standards."
}
CVE-2026-103085: WP User Manager Privilege Abuse (MEDIUM Severity, CVSS: 6.5) | Sceawere