Vulnerability in WP User Manager – User Profile Builder & Membership — CVE-2026-94079
MediumSeverity
—Estimated exploit probability
10,000+ sitesInstalls
2.9.20Fixed in
What to do now
Update WP User Manager – User Profile Builder & Membership to 2.9.20 or later.
Affected versions
- Everything up to and including 2.9.19
Affected: WP User Manager – User Profile Builder & Membership (plugin, wp-user-manager)
What the vulnerability is
The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.9.19. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.