CVE-2026-18960: Unknown Block User Account
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Affected products
- Unknown Block User Account: before 2.0.1 (fixed in 2.0.1)
Published 2026-08-10. Last modified 2026-08-26.