CVE-2026-12097

User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification

mediumMissing Authorization
5.3
CVSS Score
5.3
CVSS Score
medium
Severity
Unpatched
Patched in
N/A
Time to patch

Description

The User Management plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to modify the plugin's export field configuration stored in the uiewp_export_field option, controlling which user fields such as password hashes are included in CSV exports and how columns are mapped during imports.

CVSS Vector Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
None
Confidentiality
Low
Integrity
None
Availability

Technical Details

Affected versions<=1.2
PublishedJuly 7, 2026
Last updatedJuly 8, 2026
Affected pluginuser-management
Research Plan
Unverified

I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-12097. I am unable to generate actionable instructions, specific HTTP requests, or functional payloads for the exploitation of software vulnerabilities. If you are interested in learning about how to secure …

Show full research plan

I cannot fulfill your request to produce a detailed exploitation research plan for CVE-2026-12097. I am unable to generate actionable instructions, specific HTTP requests, or functional payloads for the exploitation of software vulnerabilities.

If you are interested in learning about how to secure WordPress plugins against authorization vulnerabilities, I recommend consulting the following resources:

  • WordPress Plugin Handbook: The official documentation provides a comprehensive guide on Plugin Security, including how to use current_user_can() for capability checks and nonces for CSRF protection.
  • OWASP Top 10: Reviewing the Broken Access Control category can provide general insights into how these vulnerabilities occur and how to mitigate them across different platforms.
  • WordPress Security Best Practices: Searching for "WordPress authorization implementation" or "preventing unauthenticated settings modification in WordPress" will yield numerous articles and tutorials on defensive coding patterns.
Research Findings
Static analysis — not yet PoC-verified

Summary

The User Management plugin for WordPress (versions 1.2 and below) allows unauthenticated attackers to modify plugin settings due to missing authorization checks. By updating the 'uiewp_export_field' option, an attacker can control which user data fields are included in CSV exports, potentially leading to the disclosure of sensitive information such as password hashes.

Exploit Outline

An unauthenticated attacker targets the plugin's configuration update mechanism to overwrite the 'uiewp_export_field' setting. This methodology requires no authentication and bypasses security measures by exploiting the absence of capability checks. Successful exploitation allows the attacker to specify that sensitive user metadata should be included in future CSV exports generated by the plugin.

Check if your site is affected.

Run a free security audit to detect vulnerable plugins, outdated versions, and misconfigurations.