PT-2026-96662 · WordPress · Wp User Manager
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP User Manager versions prior to 2.9.19
Description
The plugin allows unauthorized modification of data because the
Connect::complete() function lacks a capability check. This function is registered on the admin init hook, which executes for any authenticated user accessing /wp-admin/, including those with Subscriber roles. The function fails to perform current user can() or nonce verification before retrieving Stripe credentials from an external service and writing the publishable key, secret key, gateway mode, and connected Stripe account ID into the wpum settings option using wpum update option() or update option(). Consequently, an authenticated attacker with Subscriber-level access or higher can hijack the site's Stripe integration by completing their own Stripe Connect OAuth flow and invoking the callback, routing all subsequent payments to the attacker's account.Recommendations
Update WP User Manager to version 2.9.19 or later.
As a temporary mitigation, restrict access to the
/wp-admin/ area for users with Subscriber-level roles.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp User Manager