Sceawere

Vulnerability Detail

CVE-2026-103086UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

UsersWP Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
3h ago
Vendor
Stiofan
Product
UsersWP
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Missing Authorization vulnerability in Stiofan UsersWP userswp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects UsersWP: from n/a through 1.2.74.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T19:17:13.403Z",
  "pubdate": "2026-10-05T19:17:13.403Z",
  "executiveSummary": "This vulnerability is classified as a Missing Authorization flaw affecting the Stiofan UsersWP plugin within the WordPress ecosystem. The vulnerability exists due to improperly configured access control security levels, which fail to sufficiently validate the authorization of users requesting specific actions or resources.\nThe flaw affects all versions of UsersWP from n/a through 1.2.74. By exploiting this gap in access control, an unauthenticated or low-privileged attacker may perform unauthorized actions that should be restricted to administrative or elevated user roles.\nThe risk implication is significant as it potentially allows for unauthorized data modification or administrative-level actions, leading to a compromise of site integrity. Exploitation does not necessarily require advanced capabilities, as the vulnerability resides in the application's core logic for authorization checks. Organizations utilizing this plugin are exposed until updates are applied or access controls are manually enforced.",
  "technicalDetails": "The vulnerability originates from an inadequate implementation of access control checks within the UsersWP plugin logic. In secure web application development, authorization must be validated server-side for every request that performs sensitive operations or accesses restricted data. In the case of UsersWP, the vulnerable components fail to properly verify the security level or capabilities of the requester before processing the action.\nThe root cause is a failure to properly leverage WordPress core security functions, such as 'current_user_can()' or nonce verification, within the plugin's request handling hooks. When these checks are omitted, the plugin assumes that a request is valid regardless of the user's logged-in status or assigned role.\nThe attack flow proceeds as follows: First, an attacker identifies an endpoint or AJAX action handled by the plugin that is not protected by an authorization gate. The attacker then crafts a malicious request targeted at these endpoints. Because the plugin does not validate the requester's identity or permissions, the backend server processes the request as a legitimate command. This allows the attacker to interact with plugin-specific functions that manipulate user data, settings, or other sensitive configuration variables.\nSince the vulnerability lies within the plugin’s request-handling mechanism, the attack vector is exposed to anyone with network access to the target WordPress installation. No specific authentication is required, as the vulnerability itself removes the requirement for proper authentication/authorization. Once the request is accepted, the plugin executes the function logic, which may involve database updates, creation of user profiles, or modification of security settings depending on the specific vulnerable endpoint.\nThe impact is determined by the specific functions exposed by the lack of authorization. If the vulnerable endpoints allow modification of account details or administrative settings, an attacker could potentially escalate privileges, modify user information, or exfiltrate sensitive data. Post-exploitation, the attacker maintains influence over the affected user records or site settings, which may be leveraged for further persistence within the WordPress environment. This vulnerability demonstrates a critical failure in the Principle of Least Privilege, as the application fails to restrict access to sensitive operations, providing an unintended bypass mechanism for attackers."
}
CVE-2026-103086: UsersWP Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 6.5) | Sceawere