Impact
WordPress WP User Manager plugin versions up to 2.9.19 contain an unauthenticated broken access control flaw that lets an attacker invoke privileged actions or retrieve sensitive information without authentication. The weakness stems from missing authorization checks and is classified under CWE‑862, resulting in potential confidentiality and integrity compromise for managed user data.
Affected Systems
Any WordPress site that installs WP User Manager plugin version 2.9.19 or earlier is affected. The plugin is widely used for user account management in both public and private WordPress deployments.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation. The attack path is a web‑based request to the plugin’s administration endpoints, which an attacker can perform without user credentials, making the flaw potentially exploitable in exposed WordPress installations.
OpenCVE Enrichment