Wpusermanager
Wpusermanager WP User Manager: vulnerabilidades y CVE
Wpusermanager WP User Manager tiene 10 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses6
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-94079 | Media (5.3) | 0.22% | — | 23 sept 2026 | Unauthenticated Broken Access Control in WP User Manager <= 2.9.19 versions. |
| CVE-2026-18345 | Media (4.3) | 0.20% | — | 22 sept 2026 | The WP User Manager plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Connect::complete() function in versions up to, and including, 2.9.18. The function is… |
| CVE-2026-49766 | Crítica (9.9) | 0.55% | — | 15 jun 2026 | Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. |
| CVE-2026-9290 | Alta (7.5) | 2.7% | — | 6 jun 2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it… |
| CVE-2025-13320 | Media (6.8) | 0.82% | — | 12 dic 2025 | The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update… |
| CVE-2025-60245 | Crítica (9.8) | 0.49% | — | 6 nov 2025 | Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12. |
| CVE-2024-10537 | Media (4.3) | 0.38% | — | 23 nov 2024 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to,… |
| CVE-2024-10216 | Media (4.3) | 0.44% | — | 23 nov 2024 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in… |
| CVE-2024-43336 | Media (4.3) | 0.18% | — | 26 ago 2024 | Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager WP User Manager wp-user-manager.This issue affects WP User Manager: from n/a through <= 2.9.10. |
| CVE-2021-24655 | Alta (7.5) | 1.0% | — | 17 jul 2022 | The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.