Sceawere
Vulnerability Detail
CVE-2026-88827UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Disable Users Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Disable Users
- Attack Type
- CWE-287 Improper Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:27.267Z",
"pubdate": "2026-10-11T07:17:27.267Z",
"executiveSummary": "The Disable Users WordPress plugin, versions through 1.0.5, contains an authentication bypass vulnerability. This flaw stems from improper enforcement of account-disabling controls across all WordPress authentication vectors.\nSpecifically, while the plugin is intended to prevent disabled accounts from accessing the system, it fails to sanitize or intercept specific alternative authentication paths. This allows a user whose account has been explicitly marked as disabled by an administrator to retain active access to the application.\nThe vulnerability grants unauthorized access to previously revoked accounts, effectively negating the intended security policy enforced by administrative personnel. Attackers possessing valid credentials for a disabled account can continue to perform actions with the privileges originally assigned to that user, including administrative actions if the compromised account held high-level permissions.\nThe impact is significant, as it undermines the integrity of identity management and access control within the WordPress environment. Exploitation does not require elevated privileges beyond the credentials of the account the administrator intended to disable. This vulnerability highlights a failure in the plugin’s capability to serve as a comprehensive access control mechanism across the entire WordPress authentication lifecycle.",
"technicalDetails": "The vulnerability is rooted in a logic flaw within the Disable Users plugin's authentication hooks or filtering mechanisms. WordPress supports multiple authentication paths, including standard form-based login, XML-RPC, and REST API authentication.\nThe root cause is the plugin's failure to uniformly implement a verification check during the authentication process. Instead of providing a global, exhaustive filter that blocks authentication requests for users flagged as disabled, the plugin likely relies on specific, incomplete hooks that do not intercept all authentication attempts.\nIn a standard WordPress environment, authentication often bypasses localized plugins if the plugin does not properly hook into the low-level 'authenticate' filter. When an administrator disables a user, they expect the system to deny any subsequent authentication attempts, regardless of the entry point. Because the Disable Users plugin does not enforce this state across all available authentication interfaces, an attacker can utilize alternative protocols—such as XML-RPC or specific login endpoints—to bypass the plugin’s intended logic.\nThe attack flow is straightforward: 1) An administrator identifies a compromised or unauthorized account and triggers the 'disable' function provided by the plugin. 2) The plugin updates the user meta or status indicator to reflect the disabled state. 3) An attacker, retaining the original username and password for the disabled account, submits an authentication request via a method not governed by the plugin’s narrow logic. 4) The WordPress authentication layer, seeing valid credentials, grants a session or authentication token to the user, effectively bypassing the plugin's restriction. 5) The attacker gains full access to the application with the privileges associated with that account, potentially leading to further exploitation, data exfiltration, or persistence through backdoors if the account has administrative capabilities.\nThis vulnerability is classified as an authorization bypass. The exposure is total within the application context, as it allows for the unauthorized use of valid credentials that should have been invalidated. Since the plugin operates on the server-side, this vulnerability is not mitigated by the front-end or client-side environment and persists until the authentication logic is hardened to include all potential entry points or the plugin is removed in favor of a more robust access control solution."
}