WordPress · User Management · CVE-2026-12097
**Name of the Vulnerable Software and Affected Versions**
User Management versions prior to 1.3
**Description**
An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. This allows unauthenticated attackers to modify the export field configuration stored in the `uiewp export field` option. By manipulating this setting, an attacker can control which user fields, including password hashes, are included in CSV exports and determine how columns are mapped during import processes.
**Recommendations**
Update the plugin to a version later than 1.2.