Browse all 5 CVE security advisories affecting WP User Manager. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-103085 | WordPress WP User Manager plugin <= 2.9.20 - Privilege Escalation vulnerability — WP User Manager CWE-284 | 6.5 | Medium | 2026-10-05 |
| CVE-2026-94079 | WordPress WP User Manager plugin <= 2.9.19 - Broken Access Control vulnerability — WP User Manager CWE-862 | 5.3 | Medium | 2026-09-23 |
| CVE-2026-49766 | WordPress WP User Manager plugin <= 2.9.16 - Arbitrary File Deletion vulnerability — WP User Manager CWE-22 | 9.9 | Critical | 2026-06-15 |
| CVE-2025-60245 | WordPress WP User Manager plugin <= 2.9.12 - PHP Object Injection vulnerability — WP User Manager CWE-502 | 9.8 | Critical | 2025-11-06 |
| CVE-2024-43336 | WordPress WP User Manager – User Profile Builder & Membership plugin <= 2.9.10 - Cross Site Request Forgery (CSRF) vulnerability — WP User Manager CWE-352 | 4.3 | Medium | 2024-08-26 |
This page lists every published CVE security advisory associated with WP User Manager. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.