Extension WordPress
Vulnérabilités WP User Manager – User Profile Builder & Membership
Cette page rassemble les failles publiées pour WP User Manager – User Profile Builder & Membership, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WP User Manager – User Profile Builder & Membership
9 fiches
WP User Manager – User Profile Builder & Membership <= 2.9.16 – Authenticated (Subscriber+) Arbitrary File Deletion
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in all versions up to, and including, 2.9.16. This makes it possible for…
*-2.9.16
2.9.17
05/06/2026
WP User Manager <= 2.9.17 – Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.17 via the (profile template scope) function. This makes it possible for…
*-2.9.17
2.9.18
05/06/2026
WP User Manager <= 2.9.12 – Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter
The WP User Manager plugin for WordPress is vulnerable to Arbitrary File Deletion in all versions up to, and including, 2.9.12. This is due to insufficient validation of user-supplied file paths in the profile update functionality combined with…
*-2.9.12
2.9.13
11/12/2025
User Manager <= 2.9.12 – Authenticated (Subscriber+) PHP Object Injection
The User Manager plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.9.12 via deserialization of untrusted input. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject…
*-2.9.12
2.9.13
19/05/2025
WP User Manager – User Profile Builder & Membership <= 2.9.11 – Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'add_sidebar' and 'remove_sidebar' functions in all versions up to, and…
*-2.9.11
2.9.12
22/11/2024
WP User Manager – User Profile Builder & Membership <= 2.9.11 – Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the validate_user_meta_key() function in all versions up to, and including, 2.9.11.…
*-2.9.11
2.9.12
22/11/2024
WP User Manager <= 2.9.10 – Cross-Site Request Forgery
The WP User Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.9.10. This is due to missing or incorrect nonce validation on the fix_data_installation() function. This makes it possible for…
*-2.9.10
2.9.11
16/08/2024
WP User Manager <= 2.6.2 – Arbitrary User Password Reset
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the password of is related to the reset key given. As a result, any authenticated user can reset the password (to…
*-2.6.2
2.6.3
22/09/2021
User Registration < 2.0.2 – Authenticated Stored Cross-Site Scripting
The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their…
[*, 2.0.2)
2.0.2
06/09/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.