PT-2026-31078 · WordPress · Users Manager – Pn+1

Published

2026-04-08

·

Updated

2026-04-13

·

CVE-2026-4003

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Users manager – PN plugin for WordPress versions up to and including 1.1.15
Description The Users manager – PN plugin for WordPress is susceptible to a privilege escalation issue due to a flaw in authorization logic. Specifically, the userspn ajax nopriv server() function, within the 'userspn form save' case, fails to properly verify user authentication when a non-empty user id is provided. This allows attackers to bypass authentication checks and update arbitrary user metadata using the update user meta() function. The required nonce ('userspn-nonce') for this AJAX endpoint is publicly exposed, further weakening security controls. This allows unauthenticated attackers to modify user metadata, including the userspn secret token field.
Recommendations Update Users manager – PN plugin for WordPress to a version later than 1.1.15.

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4003

Affected Products

Users Manager – Pn
Wordpress