Description
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects New User Approve: from n/a through 3.2.8.
Published: 2026-08-20
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the New User Approve plugin that allows attackers to bypass the plugin’s built‑in access control checks. Because the plugin mediates who can approve new WordPress users, the flaw enables an attacker to create or approve user accounts without the required permissions. The weakness is classified as CWE‑862, indicating improper authorization.

Affected Systems

Affected systems include any deployment of the myCred New User Approve plugin with versions up to and including 3.2.8. The plugin is a WordPress component, so any site that installs or continues to use these versions is potentially vulnerable unless the plugin is upgraded to at least 3.2.9.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of explicit attack vector information in the advisory suggests the attack may originate from the web interface that exposes the plugin’s approval functionality; any user with access to that interface could potentially exploit the flaw. The vendor’s recommendation is to apply the patch by upgrading to the latest version, which removes the missing authorization checks.

Generated by OpenCVE AI on August 20, 2026 at 20:22 UTC.

Remediation

Vendor Solution

Update the WordPress New User Approve Plugin to the latest available version (at least 3.2.9).


OpenCVE Recommended Actions

  • Update the WordPress New User Approve Plugin to version 3.2.9 or later.
  • Review and restrict WordPress user roles so that only trusted administrators can approve new users.
  • Perform a security audit of the remaining plugin configuration to ensure no other unauthorized access paths remain; disable or uninstall the plugin if it is not needed.

Generated by OpenCVE AI on August 20, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8.
Title WordPress New User Approve plugin <= 3.2.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:27.038Z

Reserved: 2026-02-25T12:14:34.737Z

Link: CVE-2026-28163

cve-icon Vulnrichment

Updated: 2026-08-20T16:18:58.247Z

cve-icon NVD

Status : Received

Published: 2026-08-20T13:17:27.100

Modified: 2026-08-20T17:17:28.483

Link: CVE-2026-28163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:30:05Z

Weaknesses