CVE · Medium

CVE-2024-10216 — WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10216 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12 Missing Authorization Medium 4.3 < 2.9.12 2.9.12 2024-11-22

CVE-2024-10216

The WP User Manager plugin through version 2.9.11 contains a capability check bypass in its 'add_sidebar' and 'remove_sidebar' functions that allows authenticated users with basic subscriber privileges or higher to arbitrarily add or remove Carbon Fields custom sidebars when the Carbon Fields plugin is active. This vulnerability enables low-privileged attackers to modify site data without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.