{"api_version":"1","generated_at":"2026-08-12T11:39:00+00:00","cve":"CVE-2026-18035","urls":{"html":"https://cve.report/CVE-2026-18035","api":"https://cve.report/api/cve/CVE-2026-18035.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-18035","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-18035"},"summary":{"title":"User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API","description":"The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-12 06:19:22","updated_at":"2026-08-12 06:19:22"},"problem_types":["CWE-862 Missing Authorization"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/9c5cae62-4c4c-434b-ae40-4654b257803f/","name":"https://wpscan.com/vulnerability/9c5cae62-4c4c-434b-ae40-4654b257803f/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-18035","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-18035","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"User Access Manager","version":"affected 2.3.15 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Farid Narimanov","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"User Access Manager","vendor":"Unknown","versions":[{"lessThan":"2.3.15","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Farid Narimanov"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups."}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-12T06:00:16.288Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/9c5cae62-4c4c-434b-ae40-4654b257803f/"}],"source":{"discovery":"EXTERNAL"},"title":"User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-18035","datePublished":"2026-08-12T06:00:16.288Z","dateReserved":"2026-07-28T08:15:26.801Z","dateUpdated":"2026-08-12T06:00:16.288Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-12 06:19:22","lastModifiedDate":"2026-08-12 06:19:22","problem_types":["CWE-862 Missing Authorization"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"18035","Ordinal":"1","Title":"User Access Manager < 2.3.15 - Unauthenticated Restricted Conten","CVE":"CVE-2026-18035","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"18035","Ordinal":"1","NoteData":"The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups.","Type":"Description","Title":"User Access Manager < 2.3.15 - Unauthenticated Restricted Conten"}]}}}