Description
The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Account authentication bypass
Action: Immediate Patch
AI Analysis

Impact

The Disable Users plugin through version 1.0.5 fails to enforce its account‑disabling control on all authentication routes, allowing a user who has been disabled by an administrator to continue authenticating with full privileges. This flaw enables an attacker who has compromised or guessed a user’s credentials to bypass the intended denial of service and retain administrative functions. The weakness lies in improper authentication enforcement.

Affected Systems

WordPress installations that use the Disable Users plugin version 1.0.5 or earlier are affected. The attack can be exercised on any site that has XML‑RPC enabled or that supports application passwords, regardless of the site’s overall configuration.

Risk and Exploitability

The vulnerability’s CVSS score is not provided, the EPSS score is not available, and it is not listed in KEV, indicating limited public exploitation data at this time. However, because the flaw permits direct privilege retention, any compromised user account can serve as a foothold. If XML‑RPC or application passwords are in use, an attacker can send crafted requests to authenticate as the disabled account, achieving full administrative access. The attack requires only valid credentials for the disabled account and does not need special network privileges.

Generated by OpenCVE AI on October 11, 2026 at 08:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Disable Users plugin to a version newer than 1.0.5 once available.
  • If an upgrade is not available, temporarily disable or delete the plugin until an update is released.
  • Restrict XML‑RPC and application passwords by disabling them through WordPress settings or via security plugins to eliminate the identified authentication paths.

Generated by OpenCVE AI on October 11, 2026 at 08:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Disable Users WordPress plugin through 1.0.5 does not enforce its account-disabling control on all authentication paths, allowing the holder of an account an administrator has disabled to continue authenticating with the account's full privileges.
Title Disable Users <= 1.0.5 - Disabled Account Authentication Bypass via XML-RPC and Application Passwords
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:42.847Z

Reserved: 2026-09-10T09:32:36.860Z

Link: CVE-2026-88827

cve-icon Vulnrichment

Updated: 2026-10-11T11:18:32.296Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:27.267

Modified: 2026-10-11T12:17:25.853

Link: CVE-2026-88827

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:15:17Z

Weaknesses