Pricing
Case studies
Login
Start trial
WP User Manager
WP User Manager
Developer
N/A
Latest version
N/A
Installations
N/A
Last updated
WordPress Plugin
Active VDP
Report vulnerability
Vulnerabilities
Security Policy
Security Contributors
Vulnerability history
2 present
3 fixed
2 Mitigation rules
Authenticated (Subscriber+) Arbitrary File Deletion via 'current_user_avatar' Parameter vulnerability
<= 2.9.12
5 hours ago
PHP Object Injection vulnerability
<= 2.9.12
May 19, 2025
Missing Authorization to Authenticated (Subscriber+) User Meta Key Enumeration vulnerability
<= 2.9.11
Nov 22, 2024
Missing Authorization to Carbon Fields Custom Sidebar Addition/Removal vulnerability
<= 2.9.11
Nov 22, 2024
Cross Site Request Forgery (CSRF) vulnerability
<= 2.9.10
Aug 16, 2024