plugin

Wp User Manager Vulnerabilities

15 known security issues reported for the Wp User Manager WordPress plugin. Most recent disclosed Jun 5, 2026.

4 high 5 medium

Running Wp User Manager on your site? Check whether your installed version is affected.

Scan your site free

WP User Manager – User Profile Builder & Membership <= 2.9.16 - Authenticated (Subscriber+) Arbitrary File Deletion

high

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.9.16. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary fil...

CVSS:
8.1
Affected:
up to 2.9.16
Fixed in:
2.9.17
Disclosed:
Jun 5, 2026

CVE-2026-49766 on NVD →

WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter

high

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allow...

CVSS:
7.5
Affected:
up to 2.9.17
Fixed in:
2.9.18
Disclosed:
Jun 5, 2026

CVE-2026-9290 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] <= 2.9.12 (unfixed)

unknown

[en] The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. Th...

Affected:
up to 2.9.12
Fix:
No patched version reported
Disclosed:
Dec 12, 2025

CVE-2025-13320 on NVD →

WP User Manager <= 2.9.12 - Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter

medium

The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with improper handling of array inputs by PHP's filter_input() function. This ma...

CVSS:
6.8
Affected:
up to 2.9.12
Fixed in:
2.9.13
Disclosed:
Dec 11, 2025

CVE-2025-13320 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] <= 2.9.12 (unfixed)

unknown

[en] Deserialization of Untrusted Data vulnerability in WP User Manager WP User Manager wp-user-manager allows Object Injection.This issue affects WP User Manager: from n/a through <= 2.9.12.

Affected:
up to 2.9.12
Fix:
No patched version reported
Disclosed:
Nov 6, 2025

CVE-2025-60245 on NVD →

User Manager <= 2.9.12 - Authenticated (Subscriber+) PHP Object Injection

high

The User Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.12 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable...

CVSS:
7.5
Affected:
up to 2.9.12
Fixed in:
2.9.13
Disclosed:
May 19, 2025

CVE-2025-60245 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] < 2.9.12

unknown

[en] The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, wit...

Affected:
up to 2.9.12
Fixed in:
2.9.12
Disclosed:
Nov 23, 2024

CVE-2024-10216 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] < 2.9.12

unknown

[en] The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-leve...

Affected:
up to 2.9.12
Fixed in:
2.9.12
Disclosed:
Nov 23, 2024

CVE-2024-10537 on NVD →

WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal

medium

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Sub...

CVSS:
4.3
Affected:
up to 2.9.11
Fixed in:
2.9.12
Disclosed:
Nov 22, 2024

CVE-2024-10216 on NVD →

WP User Manager – User Profile Builder & Membership <= 2.9.11 - Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration

medium

The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11. This makes it possible for authenticated attackers, with Subscriber-level acc...

CVSS:
4.3
Affected:
up to 2.9.11
Fixed in:
2.9.12
Disclosed:
Nov 22, 2024

CVE-2024-10537 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] < 2.9.11

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in WP User Manager.This issue affects WP User Manager: from n/a through 2.9.10.

Affected:
up to 2.9.11
Fixed in:
2.9.11
Disclosed:
Aug 26, 2024

CVE-2024-43336 on NVD →

WP User Manager <= 2.9.10 - Cross-Site Request Forgery

medium

The WP User Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10. This is due to missing or incorrect nonce validation on the fix_data_installation() function. This makes it possible for unauthenticated attackers to fix data installation via a forged request...

CVSS:
4.3
Affected:
up to 2.9.10
Fixed in:
2.9.11
Disclosed:
Aug 16, 2024

CVE-2024-43336 on NVD →

WP User Manager &#8211; User Profile Builder &amp; Membership [wp-user-manager] < 2.6.3

unknown

[en] The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

Affected:
up to 2.6.3
Fixed in:
2.6.3
Disclosed:
Jul 17, 2022

CVE-2021-24655 on NVD →

WP User Manager <= 2.6.2 - Arbitrary User Password Reset

high

The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to an arbitrary value) of any user knowing only their ID, and gain access to their account.

CVSS:
7.5
Affected:
up to 2.6.2
Fixed in:
2.6.3
Disclosed:
Sep 22, 2021

CVE-2021-24655 on NVD →

User Registration < 2.0.2 - Authenticated Stored Cross-Site Scripting

medium

The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their pr...

CVSS:
5.4
Affected:
up to 2.0.2
Fixed in:
2.0.2
Disclosed:
Sep 6, 2021

CVE-2021-24654 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database