CVE-2026-103085: Wp User Manager

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Access Control vulnerability in WP User Manager WP User Manager wp-user-manager allows Privilege Abuse.This issue affects WP User Manager: from n/a through 2.9.20.

Affected products

Published 2026-10-05. Last modified 2026-10-06.