CVE-2026-18960
N/A
N/A
Summary
The Block User Account WordPress plugin before 2.0.1 does not enforce its account block on every authentication path, allowing a blocked user who holds an application password created before the block to retain their full role-level read and write access through the REST API.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Block User Account | 0 < 2.0.1 | affected |
Weaknesses
- CWE-287 Improper Authentication
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.