PLUGIN SECURITY

Is Wp User Manager safe?

The most customizable profiles & community builder WordPress plugin with front-end login, registration, profile customization and content restriction.

What this plugin does

  • Slug: wp-user-manager
  • Author: WP User Manager
  • 10000+ active installs
  • 94/100 rating (350 reviews on wordpress.org)
  • 726255 all-time downloads
  • On WordPress.org since 2015-07-06

communitymembersmembershipuser profileUser Registration

Maintenance status

  • Latest known version: 2.9.18
  • Last updated: 2026-05-30 9:54am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 7.4+

Known vulnerabilities

8 known CVEs on file for Wp User Manager. Reported between 2021 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-9290 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.18 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.5 < 2.9.18 2.9.18 2026-06-05 ✓ fixed in latest
CVE-2026-49766 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.17 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Critical 9.9 < 2.9.17 2.9.17 2026-06-05 ✓ fixed in latest
CVE-2025-13320 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 External Control of File Name or Path Medium 6.8 < 2.9.13 2.9.13 2025-12-11 ✓ fixed in latest
CVE-2025-60245 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.13 Deserialization of Untrusted Data Critical 9.8 < 2.9.13 2.9.13 2025-05-19 ✓ fixed in latest
CVE-2024-10216 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12 Missing Authorization Medium 4.3 < 2.9.12 2.9.12 2024-11-22 ✓ fixed in latest
CVE-2024-10537 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.12 Missing Authorization Medium 4.3 < 2.9.12 2.9.12 2024-11-22 ✓ fixed in latest
CVE-2024-43336 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.9.11 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.9.11 2.9.11 2024-08-16 ✓ fixed in latest
CVE-2021-24655 WP User Manager – User Profile Builder & Membership [wp-user-manager] < 2.6.3 Authorization Bypass Through User-Controlled Key High 7.5 < 2.6.3 2.6.3 2021-09-22 ✓ fixed in latest

How to fix it

Keep Wp User Manager updated — 2.9.18 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.