Description
Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels.

This issue affects New User Approve: from n/a through 3.2.8.
Published: 2026-08-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Update Plugin
AI Analysis

Impact

The vulnerability is a missing authorization flaw in the New User Approve plugin that allows attackers to bypass the plugin’s built‑in access control checks. Because the plugin mediates who can approve new WordPress users, the flaw enables an attacker to create or approve user accounts without the required permissions. The weakness is classified as CWE‑862, indicating improper authorization.

Affected Systems

Affected systems include any deployment of the myCred New User Approve plugin with versions up to and including 3.2.8. The plugin is a WordPress component, so any site that installs or continues to use these versions is potentially vulnerable unless the plugin is upgraded to at least 3.2.9.

Risk and Exploitability

The CVSS score of 5.3 places this issue in the medium severity range. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The lack of explicit attack vector information in the advisory suggests the attack may originate from the web interface that exposes the plugin’s approval functionality; any user with access to that interface could potentially exploit the flaw. The vendor’s recommendation is to apply the patch by upgrading to the latest version, which removes the missing authorization checks.

Generated by OpenCVE AI on August 20, 2026 at 20:22 UTC.

Remediation

Vendor Solution

Update the WordPress New User Approve Plugin to the latest available version (at least 3.2.9).


OpenCVE Recommended Actions

  • Update the WordPress New User Approve Plugin to version 3.2.9 or later.
  • Review and restrict WordPress user roles so that only trusted administrators can approve new users.
  • Perform a security audit of the remaining plugin configuration to ensure no other unauthorized access paths remain; disable or uninstall the plugin if it is not needed.

Generated by OpenCVE AI on August 20, 2026 at 20:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mycred
Mycred new User Approve
Wordpress
Wordpress wordpress
Vendors & Products Mycred
Mycred new User Approve
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects New User Approve: from n/a through 3.2.8.
Title WordPress New User Approve plugin <= 3.2.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Mycred New User Approve
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:27.038Z

Reserved: 2026-02-25T12:14:34.737Z

Link: CVE-2026-28163

cve-icon Vulnrichment

Updated: 2026-08-20T16:18:58.247Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T13:17:27.100

Modified: 2026-08-24T16:40:53.647

Link: CVE-2026-28163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:27Z

Weaknesses