← WordPress Vulnerabilities
WordPress security by component

WP User Manager

WP User Manager is a WordPress component with 8 published CVE records in this archive. The latest tracked vulnerability was published Jun 15, 2026; the highest CVE/CNA score is 9.9.

Plugin slug: wp-user-manager

CVE-2026-49766: WP User Manager: Arbitrary file deletion

WP User Manager is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.9.16.

PublishedJun 15, 2026
Known safe version2.9.17
Safe version
Jun 15, 2026 CVE-2026-49766
WP User Manager: Arbitrary file deletion
WP User Manager is affected by arbitrary file deletion. Exposure depends on how the affected operation is made reachable by the site. A successful request can remove files outside the intended scope and may make the site unavailable. The published affected range is n/a through 2.9.16.
2.9.17
CVE9.9
NVDPending
Jun 06, 2026 CVE-2026-9290
WP User Manager – User Profile Builder & Membership: Filesystem traversal
WP User Manager – User Profile Builder & Membership is affected by filesystem traversal. The vulnerable path is reachable without authentication. A crafted path can escape the intended directory and reach files or directories elsewhere on the server. The published affected range is <= 2.9.17.
> 2.9.17
CVE7.5
NVDPending
Dec 12, 2025 CVE-2025-13320
WP User Manager: Code execution
WP User Manager is affected by code execution. Exploitation requires at least subscriber-level access. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE6.8
NVDPending
Nov 06, 2025 CVE-2025-60245
WP User Manager: Code execution
WP User Manager is affected by code execution. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can run attacker-controlled code in the WordPress hosting account.
See mitigation notes
CVE9.8
NVDPending
Nov 23, 2024 CVE-2024-10537
WP User Manager – User Profile Builder & Membership: A security weakness
WP User Manager – User Profile Builder & Membership is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Nov 23, 2024 CVE-2024-10216
WP User Manager – User Profile Builder & Membership: A security weakness
WP User Manager – User Profile Builder & Membership is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 26, 2024 CVE-2024-43336
WP User Manager: Cross-site request forgery
WP User Manager is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3
Jul 17, 2022 CVE-2021-24655
WP User Manager: A security weakness
WP User Manager is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE7.5
NVD7.5