


Perceptive Security
SOC/SIEM Consultancy

The Users manager – PN plugin for WordPress is vulnerable to Privilege Escalation via Arbitrary User Meta Update in all versions up to and including 1.1.15. Thi…
Published:
7 April 2026 at 22:00:00
Alert date:
8 April 2026 at 22:09:50
Source:
nvd.nist.gov
Web Technologies
The Users manager – PN plugin for WordPress versions up to 1.1.15 contains a privilege escalation vulnerability that allows unauthenticated attackers to update arbitrary user metadata. The flaw exists in the userspn_ajax_nopriv_server() function where authorization logic only blocks users when user_id is empty, but bypasses checks when a non-empty user_id is provided. Additionally, the security nonce is exposed to all visitors through wp_localize_script, making the nonce check ineffective. Attackers can exploit this to modify any user's metadata, including sensitive fields like userspn_secret_token.
Technical details
Mitigation steps:
Affected products:
WordPress Users manager – PN plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-4003
https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php#L186
https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php#L190
https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-ajax-nopriv.php#L233
https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-common.php#L168
https://plugins.trac.wordpress.org/browser/userspn/tags/1.0.31/includes/class-userspn-functions-user.php#L235
https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-ajax-nopriv.php#L186
https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-ajax-nopriv.php#L190
https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-ajax-nopriv.php#L233
https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-common.php#L168
https://plugins.trac.wordpress.org/browser/userspn/trunk/includes/class-userspn-functions-user.php#L235
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3491109%40userspn&new=3491109%40userspn&sfp_email=&sfph_mail=
https://www.wordfence.com/threat-intel/vulnerabilities/id/27bb60c1-43fa-4a18-b9ca-059535b0d5b6?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
