plugin

User Access Manager Vulnerabilities

11 known security issues reported for the User Access Manager WordPress plugin. Most recent disclosed Aug 10, 2026.

2 high 5 medium

Running User Access Manager on your site? Check whether your installed version is affected.

Scan your site free

User Access Manager <= 2.3.14 - Missing Authorization

medium

The User Access Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.3.14
Fixed in:
2.3.15
Disclosed:
Aug 10, 2026

CVE-2026-18035 on NVD →

User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection

medium

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and sub...

CVSS:
6.5
Affected:
up to 2.3.12
Fixed in:
2.3.13
Disclosed:
Aug 4, 2026

CVE-2026-15281 on NVD →

User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter

high

The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Th...

CVSS:
7.5
Affected:
up to 2.3.15
Fixed in:
2.3.16
Disclosed:
Aug 1, 2026

CVE-2026-18352 on NVD →

User Access Manager [user-access-manager] < 2.2.18

unknown

[en] The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.

Affected:
up to 2.2.18
Fixed in:
2.2.18
Disclosed:
Aug 30, 2023

CVE-2022-1601 on NVD →

User Access Manager <= 2.2.16 - IP Spoofing

medium

The User Access Manager plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.2.16. This is due to insufficient restrictions, and the prioritization of REMOTE_ADDR, on where the IP Address information is being retrieved for access restrictions. Attackers can supply the X-Forwarde...

CVSS:
5.3
Affected:
up to 2.2.16
Fixed in:
2.2.18
Disclosed:
Aug 4, 2023

CVE-2022-1601 on NVD →

User Access Manager [user-access-manager] < 1.2

unknown

[en] The user-access-manager plugin before 1.2 for WordPress has CSRF.

Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Aug 20, 2019

CVE-2011-5328 on NVD →

User Access Manager <= 1.2.14 - Reflected Cross-Site Scripting

medium

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

CVSS:
6.1
Affected:
up to 1.2.14
Fixed in:
2.0.0
Disclosed:
Sep 5, 2017

User Access Manager <= 2.0.8 - Reflected Cross-Site Scripting

medium

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute...

CVSS:
6.1
Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Sep 5, 2017

User Access Manager [user-access-manager] < 2.0.0

unknown

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Sep 5, 2017

User Access Manager [user-access-manager] < 2.0.9

unknown

The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute...

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Sep 5, 2017

User Access Manager < 1.2 - Cross-Site Request Forgery

high

The user-access-manager plugin before 1.2 for WordPress has CSRF.

CVSS:
8.8
Affected:
up to 1.2
Fixed in:
1.2
Disclosed:
Oct 11, 2011

CVE-2011-5328 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database