TopVuln

High-risk vulnerability digests

CVE-2026-4003

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-04-08 05:16:06
EPSS
0.2% probability · 47.4th percentile — 2026-05-12
Affected versions
Users Manager – PN plugin <= 1.1.15 (WordPress)
Summary
Flawed authorization logic in the plugin's AJAX endpoint allows unauthenticated attackers to update arbitrary user metadata for any account on the site. Nonce protection is ineffective because nonces are publicly exposed to all visitors. Attackers can modify administrative account credentials to gain full site access.
Remediation
Update the Users Manager – PN plugin to a version after 1.1.15 that fixes the authorization flaw. If no patch is released, remove the plugin from your WordPress installation to eliminate the risk.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.