Description
The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.
Published: 2026-07-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The User Management plugin for WordPress contains a missing authorization check that lets an unauthenticated attacker alter the plugin’s export field configuration. By modifying the uiewp_export_field option, an attacker can add fields such as password hashes to CSV exports or change import column mappings, thereby enabling the leakage of sensitive authentication data and potentially compromising user import processes.

Affected Systems

This problem arises in the User Management plugin developed by Saadiqbal on WordPress sites that have the plugin installed in any version up to and including 1.2; sites that have not installed a later version or do not apply the patch are affected.

Risk and Exploitability

The CVSS score of 5.3 is exploitable without authentication; the attack vector is low‑effort. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. An attacker can send a crafted request to the plugin’s settings endpoint and modify the export configuration, creating an opportunity to exfiltrate password hashes in CSV files.

Generated by OpenCVE AI on July 29, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply an update of the User Management plugin that is newer than 1.2 to remove the missing authorization check.
  • If an update is not available, deactivate or uninstall the plugin to prevent unauthorized modification of export settings.
  • Monitor server logs for attempts to access the plugin’s settings endpoints and verify that no export configuration changes include sensitive fields.
  • Examine any existing CSV export files and delete those that contain password hashes or other confidential data.

Generated by OpenCVE AI on July 29, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Saadiqbal
Saadiqbal user Management
Wordpress
Wordpress wordpress
Vendors & Products Saadiqbal
Saadiqbal user Management
Wordpress
Wordpress wordpress

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Description The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.
Title User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Saadiqbal User Management
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-08T13:12:59.152Z

Reserved: 2026-06-12T14:14:04.136Z

Link: CVE-2026-12097

cve-icon Vulnrichment

Updated: 2026-07-08T13:12:55.714Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses