Impact
The Disable Users plugin through version 1.0.5 fails to enforce its account‑disabling control on all authentication routes, allowing a user who has been disabled by an administrator to continue authenticating with full privileges. This flaw enables an attacker who has compromised or guessed a user’s credentials to bypass the intended denial of service and retain administrative functions. The weakness lies in improper authentication enforcement.
Affected Systems
WordPress installations that use the Disable Users plugin version 1.0.5 or earlier are affected. The attack can be exercised on any site that has XML‑RPC enabled or that supports application passwords, regardless of the site’s overall configuration.
Risk and Exploitability
The vulnerability’s CVSS score is not provided, the EPSS score is not available, and it is not listed in KEV, indicating limited public exploitation data at this time. However, because the flaw permits direct privilege retention, any compromised user account can serve as a foothold. If XML‑RPC or application passwords are in use, an attacker can send crafted requests to authenticate as the disabled account, achieving full administrative access. The attack requires only valid credentials for the disabled account and does not need special network privileges.
OpenCVE Enrichment