Impact
The User Management plugin for WordPress contains a missing authorization check that lets an unauthenticated attacker alter the plugin’s export field configuration. By modifying the uiewp_export_field option, an attacker can add fields such as password hashes to CSV exports or change import column mappings, thereby enabling the leakage of sensitive authentication data and potentially compromising user import processes.
Affected Systems
This problem arises in the User Management plugin developed by Saadiqbal on WordPress sites that have the plugin installed in any version up to and including 1.2; sites that have not installed a later version or do not apply the patch are affected.
Risk and Exploitability
The CVSS score of 5.3 is exploitable without authentication; the attack vector is low‑effort. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog. An attacker can send a crafted request to the plugin’s settings endpoint and modify the export configuration, creating an opportunity to exfiltrate password hashes in CSV files.
OpenCVE Enrichment