WP User Manager – User Profile Builder & Membership <= 2.9.16 - Authenticated (Subscriber+) Arbitrary File Deletion
high
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.9.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary fil...
- CVSS:
- 8.1
- Affected:
- up to 2.9.16
- Fixed in:
- 2.9.17
- Disclosed:
- Jun 5, 2026
CVE-2026-49766 on NVD →
WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
high
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allow...
- CVSS:
- 7.5
- Affected:
- up to 2.9.17
- Fixed in:
- 2.9.18
- Disclosed:
- Jun 5, 2026
CVE-2026-9290 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] <= 2.9.12 (unfixed)
unknown
[en] The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. Th...
- Affected:
- up to 2.9.12
- Fix:
- No patched version reported
- Disclosed:
- Dec 12, 2025
CVE-2025-13320 on NVD →
WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter
medium
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This ma...
- CVSS:
- 6.8
- Affected:
- up to 2.9.12
- Fixed in:
- 2.9.13
- Disclosed:
- Dec 11, 2025
CVE-2025-13320 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] <= 2.9.12 (unfixed)
unknown
[en] Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.
- Affected:
- up to 2.9.12
- Fix:
- No patched version reported
- Disclosed:
- Nov 6, 2025
CVE-2025-60245 on NVD →
User Manager <= 2.9.12 - Authenticated (Subscriber+) PHP Object Injection
high
The User Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.12 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...
- CVSS:
- 7.5
- Affected:
- up to 2.9.12
- Fixed in:
- 2.9.13
- Disclosed:
- May 19, 2025
CVE-2025-60245 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12
unknown
[en] The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, wit...
- Affected:
- up to 2.9.12
- Fixed in:
- 2.9.12
- Disclosed:
- Nov 23, 2024
CVE-2024-10216 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12
unknown
[en] The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-leve...
- Affected:
- up to 2.9.12
- Fixed in:
- 2.9.12
- Disclosed:
- Nov 23, 2024
CVE-2024-10537 on NVD →
WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal
medium
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Sub...
- CVSS:
- 4.3
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.12
- Disclosed:
- Nov 22, 2024
CVE-2024-10216 on NVD →
WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration
medium
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level acc...
- CVSS:
- 4.3
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.12
- Disclosed:
- Nov 22, 2024
CVE-2024-10537 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.11
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager.This issue affects WP User Manager: from n/a through 2.9.10.
- Affected:
- up to 2.9.11
- Fixed in:
- 2.9.11
- Disclosed:
- Aug 26, 2024
CVE-2024-43336 on NVD →
WP User Manager <= 2.9.10 - Cross-Site Request Forgery
medium
The WP User Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10. This is due to missing or incorrect nonce validation on the fix_data_installation() function. This makes it possible for unauthenticated attackers to fix data installation via a forged request...
- CVSS:
- 4.3
- Affected:
- up to 2.9.10
- Fixed in:
- 2.9.11
- Disclosed:
- Aug 16, 2024
CVE-2024-43336 on NVD →
WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.6.3
unknown
[en] The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
- Affected:
- up to 2.6.3
- Fixed in:
- 2.6.3
- Disclosed:
- Jul 17, 2022
CVE-2021-24655 on NVD →
WP User Manager <= 2.6.2 - Arbitrary User Password Reset
high
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.
- CVSS:
- 7.5
- Affected:
- up to 2.6.2
- Fixed in:
- 2.6.3
- Disclosed:
- Sep 22, 2021
CVE-2021-24655 on NVD →
User Registration < 2.0.2 - Authenticated Stored Cross-Site Scripting
medium
The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their pr...
- CVSS:
- 5.4
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Sep 6, 2021
CVE-2021-24654 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database