PT-2026-96662 · WordPress · Wp User Manager

·

CVE-2026-18345

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions WP User Manager versions prior to 2.9.19
Description The plugin allows unauthorized modification of data because the Connect::complete() function lacks a capability check. This function is registered on the admin init hook, which executes for any authenticated user accessing /wp-admin/, including those with Subscriber roles. The function fails to perform current user can() or nonce verification before retrieving Stripe credentials from an external service and writing the publishable key, secret key, gateway mode, and connected Stripe account ID into the wpum settings option using wpum update option() or update option(). Consequently, an authenticated attacker with Subscriber-level access or higher can hijack the site's Stripe integration by completing their own Stripe Connect OAuth flow and invoking the callback, routing all subsequent payments to the attacker's account.
Recommendations Update WP User Manager to version 2.9.19 or later. As a temporary mitigation, restrict access to the /wp-admin/ area for users with Subscriber-level roles.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18345

Affected Products

Wp User Manager