User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API
Summary
| CVE | CVE-2026-18035 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-12 06:19:22 UTC |
| Updated | 2026-08-12 06:19:22 UTC |
| Description | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups. |
Risk And Classification
Problem Types: CWE-862 Missing Authorization
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | User Access Manager | affected 2.3.15 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/9c5cae62-4c4c-434b-ae40-4654b257803f | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Farid Narimanov (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.