User Access Manager <= 2.3.14 - Missing Authorization
medium
The User Access Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.14. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.3.14
- Fixed in:
- 2.3.15
- Disclosed:
- Aug 10, 2026
CVE-2026-18035 on NVD →
User Access Manager <= 2.3.12 - Authenticated (Subscriber+) SQL Injection
medium
The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This is due to insufficient validation on the objectId value stored in the saveAjaxAttachmentData() function and sub...
- CVSS:
- 6.5
- Affected:
- up to 2.3.12
- Fixed in:
- 2.3.13
- Disclosed:
- Aug 4, 2026
CVE-2026-15281 on NVD →
User Access Manager <= 2.3.15 - Unauthenticated Arbitrary File Read via 'uamgetfile' Parameter
high
The User Access Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.3.15 via the 'uamgetfile' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Th...
- CVSS:
- 7.5
- Affected:
- up to 2.3.15
- Fixed in:
- 2.3.16
- Disclosed:
- Aug 1, 2026
CVE-2026-18352 on NVD →
User Access Manager [user-access-manager] < 2.2.18
unknown
[en] The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible for attackers to access restricted content in certain situations.
- Affected:
- up to 2.2.18
- Fixed in:
- 2.2.18
- Disclosed:
- Aug 30, 2023
CVE-2022-1601 on NVD →
User Access Manager <= 2.2.16 - IP Spoofing
medium
The User Access Manager plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.2.16. This is due to insufficient restrictions, and the prioritization of REMOTE_ADDR, on where the IP Address information is being retrieved for access restrictions. Attackers can supply the X-Forwarde...
- CVSS:
- 5.3
- Affected:
- up to 2.2.16
- Fixed in:
- 2.2.18
- Disclosed:
- Aug 4, 2023
CVE-2022-1601 on NVD →
User Access Manager [user-access-manager] < 1.2
unknown
[en] The user-access-manager plugin before 1.2 for WordPress has CSRF.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Aug 20, 2019
CVE-2011-5328 on NVD →
User Access Manager <= 1.2.14 - Reflected Cross-Site Scripting
medium
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- CVSS:
- 6.1
- Affected:
- up to 1.2.14
- Fixed in:
- 2.0.0
- Disclosed:
- Sep 5, 2017
User Access Manager <= 2.0.8 - Reflected Cross-Site Scripting
medium
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute...
- CVSS:
- 6.1
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 5, 2017
User Access Manager [user-access-manager] < 2.0.0
unknown
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 1.2.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exec...
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Sep 5, 2017
User Access Manager [user-access-manager] < 2.0.9
unknown
The User Access Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter in versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that execute...
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Sep 5, 2017
User Access Manager < 1.2 - Cross-Site Request Forgery
high
The user-access-manager plugin before 1.2 for WordPress has CSRF.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Oct 11, 2011
CVE-2011-5328 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database