Description
The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Published: 2026-08-12
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The User Access Manager plugin does not apply its configured access restrictions to REST API requests. As a result, any unauthenticated user can retrieve the content of posts, pages, and custom post types that have been restricted to specific user groups. This flaw exposes information that site administrators intended to keep confidential.

Affected Systems

WordPress sites that have the User Access Manager plugin installed at a version older than 2.3.15 are affected. The vulnerability is confined to the plugin; no particular WordPress core version is cited.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The flaw does not require authentication; an attacker can simply send REST API requests to the exposed endpoints to download restricted content. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation probability. Based on the description, it is inferred that an attacker can use standard REST API calls to gather this information from any public WordPress site using the vulnerable plugin.

Generated by OpenCVE AI on August 13, 2026 at 01:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the User Access Manager plugin to version 2.3.15 or newer.
  • If an upgrade is not immediately possible, restrict the REST API routes that expose post, page, and custom post data by configuring server‑side access controls (e.g., firewall rules or .htaccess) so that only authenticated requests can reach those endpoints.
  • Review other installed plugins for similar REST API access‑control omissions and ensure they enforce proper authorization before exposing protected content.

Generated by OpenCVE AI on August 13, 2026 at 01:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared User Access Manager Project
User Access Manager Project user Access Manager
Wordpress
Wordpress wordpress
Vendors & Products User Access Manager Project
User Access Manager Project user Access Manager
Wordpress
Wordpress wordpress

Wed, 12 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.
Title User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
References

Subscriptions

User Access Manager Project User Access Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T17:16:14.555Z

Reserved: 2026-07-28T08:15:26.801Z

Link: CVE-2026-18035

cve-icon Vulnrichment

Updated: 2026-08-12T17:15:39.594Z

cve-icon NVD

Status : Deferred

Published: 2026-08-12T06:19:22.667

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-18035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses